Record summary

CVE-2022-24562 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.

Description

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBIOTransfer 4.0 - Remote Code Execution (RCE)ExploitDB exploitby Tomer PeledNot analyzed1 file
ExploitDB

PoC details

References

6