CVE-2022-31216: Drive Composer Link Following Local Privilege Escalation Vulnerability
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-31216.
What is the severity of CVE-2022-31216?
The severity of CVE-2022-31216 is high, with a severity value of 7.8.
What software is affected by CVE-2022-31216?
The affected software includes Abb Automation Builder (versions between 1.1.0 and 2.5.0), Abb Drive Composer (versions between 2.0 and 2.7.1), and Abb Mint Workbench (version 5866).
What can a low privileged attacker do with CVE-2022-31216?
A low privileged attacker can create and write to a file anywhere on the file system as SYSTEM with arbitrary content, as long as the file does not already exist.
Is there a fix for CVE-2022-31216?
Yes, it is recommended to update the affected software to the latest versions available in order to mitigate the vulnerability.