Logitech Sync desktop application prior to 2.4.574 - TOCTOU during installation leads to privelege escalation
CVE-2022-0915

6MEDIUM

Key Information:

Vendor

Logitech

Status
Vendor
CVE Published:
8 April 2022

What is CVE-2022-0915?

There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Logitech Sync for Windows prior to 2.4.574. Successful exploitation of these vulnerabilities may escalate the permission to the system user.

Affected Version(s)

Sync Windows prior to 2.4.574 < 2.4.574

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Karan Bamal
.