CVE-2022-23862
Last modified
CVE-2022-23862 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696 is vulnerable to JMX MLet attacks. EPSS estimates a 0.49% chance of exploitation in the next 30 days.
Description
A Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696 is vulnerable to JMX MLet attacks. Because the service did not enforce authentication and was running under the "NT Authority\System" user, an attacker is able to use the vulnerability to execute arbitrary code and elevate to the system user.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Ysoft | Safeq | 6.0 | Build53 |
References
- https://github.com/mbadanoiu/CVE-2022-23862Exploit, Third Party Advisory
- https://ysoft.comProduct
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-23862?
How severe is CVE-2022-23862?
How do I fix CVE-2022-23862?
Are you affected by CVE-2022-23862?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
