Unquoted Service Path Vulnerability in IOTransfer by IOBit
CVE-2022-37197

7.8HIGH

Key Information:

Vendor

Iobit

Vendor
CVE Published:
18 November 2022

What is CVE-2022-37197?

IOBit IOTransfer V4 is susceptible to an unquoted service path vulnerability, which can be exploited to gain elevated privileges. Attackers can potentially execute arbitrary commands through the improper handling of paths in the service configurations, leading to unauthorized access and manipulation of system resources. It is crucial for users to update their software to mitigate this security risk.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.