CVE-2022-26488
Summary
| CVE | CVE-2022-26488 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-10 17:47:00 UTC |
| Updated | 2023-11-07 03:45:00 UTC |
| Description | In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may allow a local attacker to add user-writable directories to the system search path. To exploit, an administrator must have installed Python for all users and enabled PATH entries. A non-administrative user can trigger a repair that incorrectly adds user-writable paths into PATH, enabling search-path hijacking of other users and system services. This affects Python (CPython) through 3.7.12, 3.8.x through 3.8.12, 3.9.x through 3.9.10, and 3.10.x through 3.10.2. |
Risk And Classification
Problem Types: CWE-426
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows | - | All | All | All |
| Application | Netapp | Active Iq Unified Manager | - | All | All | All |
| Application | Netapp | Ontap Select Deploy Administration Utility | - | All | All | All |
| Application | Python | Python | 3.11.0 | alpha1 | All | All |
| Application | Python | Python | 3.11.0 | alpha2 | All | All |
| Application | Python | Python | 3.11.0 | alpha3 | All | All |
| Application | Python | Python | 3.11.0 | alpha4 | All | All |
| Application | Python | Python | 3.11.0 | alpha5 | All | All |
| Application | Python | Python | 3.11.0 | alpha6 | All | All |
| Application | Python | Python | All | All | All | All |
| Application | Python | Python | All | All | All | All |
| Application | Python | Python | All | All | All | All |
| Application | Python | Python | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mailman 3 [CVE-2022-26488] Escalation of privilege via Windows installer - Security-announce - python.org | MISC | mail.python.org | |
| Mailman 3 [CVE-2022-26488] Escalation of privilege via Windows installer - Security-announce - python.org | mail.python.org | ||
| CVE-2022-26488 Python Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.