CVE-2022-28877: Local Privilege Escalation Vulnerability in F-Secure & WithSecure Windows Endpoint Products
This vulnerability allows local user to delete arbitrary file in the system and bypassing security protection which can be abused for local privilege escalation on affected F-Secure & WithSecure windows endpoint products. An attacker must have code execution rights on the victim machine prior to successful exploitation.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-28877?
CVE-2022-28877 is a vulnerability that allows a local user to delete arbitrary files in the system and bypass security protection on affected F-Secure & WithSecure Windows endpoint products, potentially resulting in local privilege escalation.
Which software is affected by CVE-2022-28877?
F-Secure Elements Endpoint Protection is affected by CVE-2022-28877.
How can an attacker exploit CVE-2022-28877?
To exploit CVE-2022-28877, the attacker must have code execution rights on the victim machine prior to successfully deleting arbitrary files and bypassing security protection.
What is the severity of CVE-2022-28877?
CVE-2022-28877 has a severity value of 6.7, which is considered medium.
How can I protect my system from CVE-2022-28877?
To protect your system from CVE-2022-28877, ensure that you have the latest security updates and patches for the affected F-Secure Elements Endpoint Protection software.