Use After Free Vulnerability in CX-Drive by Delta Electronics
CVE-2022-46282

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
21 December 2022

What is CVE-2022-46282?

A use after free vulnerability has been identified in CX-Drive versions V3.00 and earlier by Delta Electronics. This flaw can be exploited by a local attacker when a user opens a specially crafted file, potentially leading to arbitrary code execution on the affected system. It is crucial for users and administrators to apply the appropriate patches or updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

CX-Drive V3.00 and earlier

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.