CVE-2022-34866

HIGH

Passage Drive 1.4.0-1.5.1.0 & Box 1.0.0 - Local Privilege Escalation via IPC Data Verification

Title source: llm
STIX 2.1

Description

Passage Drive versions v1.4.0 to v1.5.1.0 and Passage Drive for Box version v1.0.0 contain an insufficient data verification vulnerability for interprocess communication. By running a malicious program, an arbitrary OS command may be executed with LocalSystem privilege of the Windows system where the product is running.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://jvn.jp/en/jp/JVN23766146/index.html

Scores

CVSS v3 7.8
EPSS 0.0020
EPSS Percentile 10.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (2)
yrl/passage_drive 1.4.0 - 1.5.1.0
yrl/passage_drive_for_box 1.0.0
Published Jul 20, 2022
Tracked Since Feb 18, 2026