CVE-2022-36415
Published on: Not Yet Published
Last Modified on: 08/01/2022 04:05:00 PM UTC
Certain versions of Beyond Compare from Scootersoftware contain the following vulnerability:
A DLL hijacking vulnerability exists in the uninstaller in Scooter Beyond Compare 1.8a through 4.4.2 before 4.4.3 when installed via the EXE installer. The uninstaller attempts to load DLLs out of a Windows Temp folder. If a standard user places malicious DLLs in the C:\Windows\Temp\ folder, and then the uninstaller is run as SYSTEM, the DLLs will execute with elevated privileges.
- CVE-2022-36415 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Beyond Compare Technical Support | www.scootersoftware.com text/html |
![]() |
Related QID Numbers
- 376939 Beyond Compare DLL Hijacking Vulnerability
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Scootersoftware | Beyond Compare | All | All | All | All |
- cpe:2.3:a:scootersoftware:beyond_compare:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-36415 : A DLL hijacking vulnerability exists in the uninstaller in Scooter Beyond Compare 1.8a through 4.4… twitter.com/i/web/status/1… | 2022-07-23 03:05:01 |
![]() |
New Vulnerability: CVE-2022-36415 #InceptusSecure #UnderOurProtection | 2022-07-23 05:16:01 |
![]() |
Php - CVE-2022-36415: scootersoftware.com/support.php?zz… | 2022-07-23 06:00:14 |
![]() |
CVE-2022-36415 A DLL hijacking vulnerability exists in the uninstaller in Scooter Beyond Compare 1.8a through 4.4.2… twitter.com/i/web/status/1… | 2022-07-24 07:09:12 |
![]() |
CVE-2022-36415 | 2022-07-23 03:38:39 |