CVE-2022-27502
HIGHRealVNC VNC Server 5.1.0-6.9.0 - Local Privilege Escalation via Installer Repair Operation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-27502. PoCs published by alirezac0.
AI-analyzed exploit summary This repository contains a DLL hijacking exploit for CVE-2022-27502, targeting RealVNC Server up to version 6.9.0. The exploit involves placing a malicious DLL in %TEMP% and triggering a repair operation to execute arbitrary commands (e.g., `whoami`).
Description
RealVNC VNC Server 6.9.0 through 5.1.0 for Windows allows local privilege escalation because an installer repair operation executes %TEMP% files as SYSTEM.
Exploits (1)
This repository contains a DLL hijacking exploit for CVE-2022-27502, targeting RealVNC Server up to version 6.9.0. The exploit involves placing a malicious DLL in %TEMP% and triggering a repair operation to execute arbitrary commands (e.g., `whoami`).
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H