CVE-2022-32973: Command Injection
Published Jun 21, 2022
·Updated
An authenticated attacker could create an audit file that bypasses PowerShell cmdlet checks and executes commands with administrator privileges.
Affected Software
1 affected component
Tenable Nessus<10.2.0
Event History
Jun 21, 2022
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-32973?
CVE-2022-32973 is a vulnerability that allows an authenticated attacker to create an audit file that bypasses PowerShell cmdlet checks and executes commands with administrator privileges.
2
What is the severity of CVE-2022-32973?
CVE-2022-32973 has a severity rating of critical (8.8).
3
Which software is affected by CVE-2022-32973?
Tenable Nessus up to version 10.2.0 is affected by CVE-2022-32973.
4
How can an attacker exploit CVE-2022-32973?
An attacker with authenticated access can create a specially crafted audit file to bypass PowerShell cmdlet checks and execute commands with administrator privileges.
5
Is there a fix for CVE-2022-32973?
It is recommended to upgrade to a patched version of Tenable Nessus to mitigate the vulnerability.