CVE-2022-31219: Drive Composer Link Following Local Privilege Escalation Vulnerability
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-31219?
CVE-2022-31219 is a vulnerability in the Drive Composer that allows a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content.
What is the severity of CVE-2022-31219?
The severity of CVE-2022-31219 is high with a severity value of 7.8.
Which software is affected by CVE-2022-31219?
Abb Automation Builder, Abb Drive Composer (entry version), Abb Drive Composer (pro version), and Abb Mint Workbench are affected by CVE-2022-31219.
How can an attacker exploit CVE-2022-31219?
An attacker can exploit CVE-2022-31219 by running a 'repair' operation on the Drive Composer installer file as a low-privileged user.
Is there a fix available for CVE-2022-31219?
It is recommended to update affected software to versions that are not vulnerable. Please refer to the vendor's security advisory for specific information.