CVE-2022-24618: High severity Heimdalsecurity Heimdal Premium Security vulnerability
Published Mar 9, 2022
·Updated
Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unprivileged local users to elevate privileges to SYSTEM via the "Browse For Folder" window accessible by triggering a "Repair" on the MSI package located in C:\Windows\Installer.
Affected Software
1 affected component
Heimdalsecurity Heimdal Premium Security<2.5.398
Event History
Mar 9, 2022
CVE Published
via MITRE·11:40 AM
Data Sourced
via MITRE·11:40 AM
Description
Mar 10, 2022
Data Sourced
via NVD·05:46 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-24618?
CVE-2022-24618 is a vulnerability in the Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier versions.
2
How severe is CVE-2022-24618?
CVE-2022-24618 has a severity score of 7.8, categorized as high.
3
How can unprivileged local users exploit CVE-2022-24618?
Unprivileged local users can elevate privileges to SYSTEM by triggering a "Repair" on the MSI package in C:\Windows\Installer, accessible through the "Browse For Folder" window in Heimdal.Wizard.exe installer.