First published: Mon Oct 24 2022(Updated: )
Untrusted search path vulnerability in the installer of Content Transfer (for Windows) Ver.1.3 and prior allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Sony Content Transfer | <=1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-41796.
The severity of CVE-2022-41796 is high with a CVSS score of 7.8.
The affected software for CVE-2022-41796 is Content Transfer (for Windows) Ver.1.3 and prior.
CVE-2022-41796 allows an attacker to gain privileges by using a Trojan horse DLL in an unspecified directory.
To mitigate CVE-2022-41796, it is recommended to update to a fixed version of Content Transfer (for Windows) that addresses the vulnerability.