9.8
CVE-2022-39060
- EPSS 1.04%
- Veröffentlicht 31.01.2023 08:15:08
- Zuletzt bearbeitet 21.11.2024 07:17:28
- Quelle twcert@cert.org.tw
- CVE-Watchlists
- Unerledigt
ChangingTech MegaServiSignAdapter component has a vulnerability of improper input validation. An unauthenticated remote attacker can exploit this vulnerability to access and modify HKEY_CURRENT_USER subkey (ex: AutoRUN) in Registry where malicious scripts can be executed to take control of the system or to terminate the service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Changingtec ≫ Megaservisignadapter SwPlatformwindows Version < 1.0.22.1004
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.04% | 0.77 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| twcert@cert.org.tw | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.