CVE-2022-29973

MEDIUM

exfat 1.3.0 - Information Disclosure via Deleted File Data Access

Title source: llm
STIX 2.1

Description

relan exFAT 1.3.0 allows local users to obtain sensitive information (data from deleted files in the filesystem) in certain situations involving offsets beyond ValidDataLength.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/relan/exfat/issues/185

Scores

CVSS v3 4.7
EPSS 0.0030
EPSS Percentile 21.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-770
Status published
Products (1)
exfat_project/exfat 1.3.0
Published May 02, 2022
Tracked Since Feb 18, 2026