7

CVE-2022-26488

In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may allow a local attacker to add user-writable directories to the system search path. To exploit, an administrator must have installed Python for all users and enabled PATH entries. A non-administrative user can trigger a repair that incorrectly adds user-writable paths into PATH, enabling search-path hijacking of other users and system services. This affects Python (CPython) through 3.7.12, 3.8.x through 3.8.12, 3.9.x through 3.9.10, and 3.10.x through 3.10.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Python ≫ Python Version <= 3.7.12
   Microsoft ≫ Windows Version -
Python ≫ Python Version >= 3.8.0 <= 3.8.12
   Microsoft ≫ Windows Version -
Python ≫ Python Version >= 3.9.0 <= 3.9.10
   Microsoft ≫ Windows Version -
Python ≫ Python Version >= 3.10.0 <= 3.10.2
   Microsoft ≫ Windows Version -
Python ≫ Python Version 3.11.0 Update alpha1
   Microsoft ≫ Windows Version -
Python ≫ Python Version 3.11.0 Update alpha2
   Microsoft ≫ Windows Version -
Python ≫ Python Version 3.11.0 Update alpha3
   Microsoft ≫ Windows Version -
Python ≫ Python Version 3.11.0 Update alpha4
   Microsoft ≫ Windows Version -
Python ≫ Python Version 3.11.0 Update alpha5
   Microsoft ≫ Windows Version -
Python ≫ Python Version 3.11.0 Update alpha6
   Microsoft ≫ Windows Version -
Netapp ≫ Active Iq Unified Manager Version - SwPlatform windows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.37% 0.682
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
CWE-426 Untrusted Search Path

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

https://mail.python.org/archives/list/security-announce%40python.org/thread/657Z4XULWZNIY5FRP3OWXHYKUSIH6DMN/
https://security.netapp.com/advisory/ntap-20220419-0005/
Third Party Advisory