Insecure API in IOBit IOTransfer Allows Unauthorized File System Access
CVE-2022-24562
9.8CRITICAL
What is CVE-2022-24562?
In IOBit IOTransfer version 4.3.1.1561, a serious insecurity exists allowing unauthenticated attackers to exploit the application's Airserv API. By sending crafted GET and POST requests, attackers can gain unrestricted read and write permissions to the entire file system on the victim's machine, effectively bypassing security measures and potentially leading to data theft and unauthorized remote code execution. The vulnerability underscores significant risks associated with insecure API implementations and highlights the importance of robust authentication mechanisms.
References
EPSS Score
65% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved