CVE-2022-24562

🔴 Łataj teraz

Luka w IOBit IOTransfer umożliwia zdalny dostęp do systemu plików i wykonanie kodu.

CVSS
9.8
EPSS
53.2%
Exploit
poc
Vendor
iobit
Opis źródłowy (NVD)

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.

exploit rce Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)53.2%
Opublikowano (NVD)2022-06-16 19:15:07 UTC
Ostatnia modyfikacja (NVD)2026-07-09 01:17:17 UTC
Referencje