CVE-2022-4246
Last modified
CVE-2022-4246 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A vulnerability classified as problematic has been found in Kakao PotPlayer. This affects an unknown part of the component MID File Handler. EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
A vulnerability classified as problematic has been found in Kakao PotPlayer. This affects an unknown part of the component MID File Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214623.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kakaocorp | Potplayer | All versions |
References
- https://seclists.org/fulldisclosure/2022/Nov/16Mailing List, Third Party Advisory
- https://seclists.org/fulldisclosure/2022/Nov/att-16/potplayer_7z.binThird Party Advisory
- https://vuldb.com/?id.214623Third Party Advisory
- https://seclists.org/fulldisclosure/2022/Nov/16Mailing List, Third Party Advisory
- https://seclists.org/fulldisclosure/2022/Nov/att-16/potplayer_7z.binThird Party Advisory
- https://vuldb.com/?id.214623Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-4246?
How severe is CVE-2022-4246?
How do I fix CVE-2022-4246?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-42453There are insufficient warnings when a Fixlet is imported by…6.5
- CVE-2022-42454Insights for Vulnerability Remediation (IVR) is vulnerable t…5.3
- CVE-2022-42455ASUS EC Tool driver (aka d.sys) 1beb15c90dcf7a5234ed077833a0…7.8
- CVE-2022-42457Generex CS141 through 2.10 allows remote command execution b…7.2
- CVE-2022-42458Authentication bypass using an alternate path or channel vul…9.8
- CVE-2022-42459Auth. WordPress Options Change vulnerability in Image Hover …7.2
- CVE-2022-42460Broken Access Control vulnerability leading to Stored Cross-…5.4
- CVE-2022-42461Broken Access Control vulnerability in miniOrange's Google A…8.8
- CVE-2022-42462Auth. Stored Cross-Site Scripting (XSS) vulnerability in Ade…4.8
- CVE-2022-42463OpenHarmony-v3.1.2 and prior versions have an authenication …8.8
- CVE-2022-42464OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versi…7.8
- CVE-2022-42465Improper access control in kernel mode driver for the Intel(…6.7
Are you affected by CVE-2022-4246?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
