CVE-2022-37172: High severity centos lvm2 vulnerability
Incorrect access control in the install directory (C:\msys64) of Msys2 v20220603 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-37172?
CVE-2022-37172 is classified as a high severity vulnerability due to its potential to allow authenticated attackers to execute arbitrary code.
How do I fix CVE-2022-37172?
To mitigate CVE-2022-37172, upgrade Msys2 to version 20220604 or later to address the incorrect access control in the install directory.
Who can exploit CVE-2022-37172?
CVE-2022-37172 can be exploited by authenticated attackers who have access to the install directory of Msys2 versions prior to 20220604.
What type of vulnerability is CVE-2022-37172?
CVE-2022-37172 is an access control vulnerability that allows for arbitrary code execution through overwriting binaries in the install directory.
What software is affected by CVE-2022-37172?
CVE-2022-37172 affects Msys2 versions up to and including 20220603.