CVE-2022-26057: Mint WorkBench Link Following Local Privilege Escalation Vulnerability
Vulnerabilities in the Mint WorkBench allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Mint WorkBench installer file allows a low-privileged user to run a "repair" operation on the product
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26057?
The severity of CVE-2022-26057 is high with a CVSS score of 7.8.
What is the affected software for CVE-2022-26057?
The affected software for CVE-2022-26057 is the Mint WorkBench version 5866 by Abb.
How does CVE-2022-26057 allow an attacker to create and write to a file anywhere on the file system?
CVE-2022-26057 allows a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM by running a "repair" operation using the Mint WorkBench installer file.
What can an attacker do with CVE-2022-26057?
An attacker with CVE-2022-26057 can create and write to a file anywhere on the file system as SYSTEM with arbitrary content, as long as the file does not already exist.
Is there a fix available for CVE-2022-26057?
It is recommended to update to a fixed version of the Mint WorkBench software to mitigate CVE-2022-26057.