CVE-2022-22521
7.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.3 / Impact: 5.9
Source: NVD (Secondary)
Description
In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administrative privileges to execute these binaries as admin.
Affected (1)
Products: Miele: Benchmark Programming Tool
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.72 |
References (8)
Source: info@cert.vde.com
ExploitPatchThird Party AdvisoryVDB Entry
Source: info@cert.vde.com
ExploitMailing ListPatchThird Party Advisory
Source: info@cert.vde.com
MitigationThird Party Advisory
Source: info@cert.vde.com
PatchProductRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchProductRelease NotesVendor Advisory
Timeline
No history available yet.