First published: Mon Sep 19 2022(Updated: )
The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking
Credit: cve@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains IntelliJ IDEA | <2022.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40978 refers to the vulnerability in the installer of JetBrains IntelliJ IDEA before 2022.2.2.
CVE-2022-40978 has a severity rating of 7.8 (high).
CVE-2022-40978 affects JetBrains IntelliJ IDEA versions before 2022.2.2.
EXE search order hijacking is a vulnerability where an attacker can trick Windows into executing a malicious executable by manipulating the order in which the operating system searches for executables.
To fix CVE-2022-40978, update JetBrains IntelliJ IDEA to version 2022.2.2 or newer.