CVE-2022-28877

medium

Description

This vulnerability allows local user to delete arbitrary file in the system and bypassing security protection which can be abused for local privilege escalation on affected F-Secure & WithSecure windows endpoint products. An attacker must have code execution rights on the victim machine prior to successful exploitation.

References

https://www.withsecure.com/en/support/security-advisories

https://www.f-secure.com/en/business/support-and-downloads/security-advisories

Details

Source: Mitre, NVD

Published: 2022-07-21

Updated: 2022-07-27

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:L/AC:L/Au:M/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 6.7

Vector: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Severity: Medium