CVE-2022-40978: High severity JetBrains IntelliJ IDEA vulnerability
The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains IntelliJ IDEAto a version that resolves this vulnerability.Fixed in 2022.2.2
Event History
Frequently Asked Questions
What is CVE-2022-40978?
CVE-2022-40978 refers to the vulnerability in the installer of JetBrains IntelliJ IDEA before 2022.2.2.
What is the severity of CVE-2022-40978?
CVE-2022-40978 has a severity rating of 7.8 (high).
How does CVE-2022-40978 affect JetBrains IntelliJ IDEA?
CVE-2022-40978 affects JetBrains IntelliJ IDEA versions before 2022.2.2.
What is EXE search order hijacking?
EXE search order hijacking is a vulnerability where an attacker can trick Windows into executing a malicious executable by manipulating the order in which the operating system searches for executables.
How can I fix CVE-2022-40978?
To fix CVE-2022-40978, update JetBrains IntelliJ IDEA to version 2022.2.2 or newer.