QID 379239

Date Published: 2024-02-06

QID 379239: XAMPP Windows Privilege Escalation Vulnerability (CVE-2022-47637)

XAMPP is an Apache distribution designed for easy installation. It includes MySQL, PHP and Perl CGI support.

Windows Privilege Escalation Vulnerability has been reported in XAMPP for windows platform

The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory. Common use cases execute files under C:\xampp with administrative privileges.

Affected Version:
1- Older versions upto to 8.1.12
Detection Logic:
It checks for vulnerable version of XAMPP by checking the file version on Microsoft Windows.

If this vulnerability is successfully exploited then an attacker could write to the C:\xampp directory and can execute files under C:\xampp with administrative privileges.

  • CVSS V3 rated as High - 6.7 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Update to Version 8.2.12, 8.1.25 and 8.0.30 to resolve this issue. The latest version is available for download fromXAMPP Web site.For More Information Kindly check Reference

    CVEs related to QID 379239

    Software Advisories
    Advisory ID Software Component Link
    new_xampp_20231119 URL Logo www.apachefriends.org/blog/new_xampp_20231119.html