CVE-2022-0074

HIGH EXPLOITED RANSOMWARE

OpenLiteSpeed 1.6.15-1.7.16 - Privilege Escalation via Untrusted Search Path

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-0074 has been observed exploited in the wild (reported by VulnCheck KEV), including in ransomware campaigns.

Description

Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server Container allows Privilege Escalation. This affects versions from 1.6.15 before 1.7.16.1.

Scores

CVSS v3 8.8
EPSS 0.0115
EPSS Percentile 62.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

VulnCheck KEV 2025-03-19
Ransomware Use Confirmed
CWE
CWE-426
Status published
Products (1)
litespeedtech/openlitespeed 1.6.15 - 1.7.16.1
Published Oct 27, 2022
Tracked Since Feb 18, 2026