First published: Tue Nov 29 2022(Updated: )
Insecure permissions in Chocolatey Cmder package v1.3.20 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\Cmder and all files located in that folder.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chocolatey | <=1.3.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45304 has a medium severity rating due to its potential for unauthorized access and privilege escalation.
To fix CVE-2022-45304, update the Chocolatey Cmder package to version 1.3.21 or later.
The risks associated with CVE-2022-45304 include unauthorized write access to files under C:\tools\Cmder, potentially allowing data manipulation or malicious activity.
All users on a system where the Chocolatey Cmder package version 1.3.20 or below is installed may be affected by CVE-2022-45304.
Versions 1.3.20 and below of the Chocolatey Cmder package are vulnerable to CVE-2022-45304.