CVE-2022-24618
Summary
| CVE | CVE-2022-24618 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-10 17:46:00 UTC |
| Updated | 2022-03-16 19:13:00 UTC |
| Description | Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unprivileged local users to elevate privileges to SYSTEM via the "Browse For Folder" window accessible by triggering a "Repair" on the MSI package located in C:\Windows\Installer. |
Risk And Classification
Problem Types: CWE-281
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Heimdalsecurity | Heimdal Premium Security | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Nogva Heimdal Propulsion AS – Heimdal | MISC | heimdal.com | |
| 2.5.398 PROD and 2.5.401 RC – Heimdal Security Assistance and Support | MISC | support.heimdalsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.