CVE-2022-31217: Drive Composer Link Following Local Privilege Escalation Vulnerability
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-31217?
The severity of CVE-2022-31217 is high with a score of 7.8.
How can a low privileged attacker exploit CVE-2022-31217?
A low privileged attacker can exploit CVE-2022-31217 by creating and writing to a file anywhere on the file system as SYSTEM with arbitrary content.
Which software is affected by CVE-2022-31217?
Abb Automation Builder, Abb Drive Composer, and Abb Mint Workbench are affected by CVE-2022-31217.
How can I fix CVE-2022-31217?
To fix CVE-2022-31217, it is recommended to update Abb Automation Builder, Abb Drive Composer, and Abb Mint Workbench to the latest versions.
Where can I find more information about CVE-2022-31217?
More information about CVE-2022-31217 can be found at the following link: [CVE-2022-31217](https://search.abb.com/library/Download.aspx?DocumentID=9AKK108467A0305&LanguageCode=en&DocumentPartId=&Action=Launch&_ga=2.38192870.478847987.1655218701-372504397.1647012599).