← Back

CVE-2022-28944

nvd nist
Published: May 23, 2022Modified: Jul 9, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows 5.8.22 and Network Software Scanner for Windows 2.0.8 and UnLock IT for Windows 6.1.1. The impact is: execute arbitrary code (remote). The component is: Updater. The attack vector is: To exploit this vulnerability, a user must trigger an update of an affected installation of EMCO Software. ¶¶ Multiple products from EMCO Software are affected by a remote code execution vulnerability during the update process.

Affected (9)

8 products
Msi Package Builder
Network Inventory
Network Software Scanner
Ping Monitor
Remote Installer
Remote Shutdown
Unlock It
Wakeonlan
Configuration A
7 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 9.1.4
Version 5.8.22
Version 2.0.8
Version 8.0.18
Version 6.0.13
Version 7.2.2
Version 6.1.1
Running on/withPlatform Versions
Microsoft
Windows
All versions
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Emcosoftware
Version 2.0.8
Version 2.0.8

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.