CVE-2022-38176
Published on: Not Yet Published
Last Modified on: 09/09/2022 07:26:00 PM UTC
Certain versions of Safeq from Ysoft contain the following vulnerability:
An issue was discovered in YSoft SAFEQ 6 before 6.0.72. Incorrect privileges were configured as part of the installer package for the Client V3 services, allowing for local user privilege escalation by overwriting the executable file via an alternative data stream. NOTE: this is not the same as CVE-2021-31859.
- CVE-2022-38176 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
YSoft SAFEQ Client V3 Local Privilege Escalation Vulnerability | Y Soft | www.ysoft.com text/html |
![]() |
Y Soft Corporation - Intelligent Enterprise Office Solutions | ysoft.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Ysoft | Safeq | All | All | All | All |
- cpe:2.3:a:ysoft:safeq:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-38176 : An issue was discovered in YSoft SAFEQ 6 before 6.0.72. Incorrect privileges were configured as pa… twitter.com/i/web/status/1… | 2022-09-06 21:05:05 |
![]() |
CVE-2022-38176 | 2022-09-06 22:38:22 |