CVE-2022-0915: Logitech Sync desktop application prior to 2.4.574 - TOCTOU during installation leads to privelege escalation
Published Apr 12, 2022
·Updated
There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Logitech Sync for Windows prior to 2.4.574. Successful exploitation of these vulnerabilities may escalate the permission to the system user.
Affected Software
1 affected component
Logitech Sync Windows<2.4.574
Remediation
Information
Update to 2.4.574
Event History
Apr 12, 2022
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-0915?
CVE-2022-0915 is a high severity vulnerability that allows for potential permission escalation to the system user.
2
How do I fix CVE-2022-0915?
To fix CVE-2022-0915, upgrade Logitech Sync to version 2.4.574 or later.
3
What type of vulnerability is CVE-2022-0915?
CVE-2022-0915 is a Time-of-check Time-of-use (TOCTOU) race condition vulnerability.
4
What systems are affected by CVE-2022-0915?
CVE-2022-0915 affects Logitech Sync for Windows prior to version 2.4.574.
5
What are the potential consequences of exploiting CVE-2022-0915?
Exploiting CVE-2022-0915 may allow an attacker to escalate privileges to that of the system user.