First published: Sun Mar 19 2023(Updated: )
ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the current working directory, which may be any directory in which an ONLYOFFICE document is located.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ONLYOFFICE | <=7.3.0 | |
Linux Kernel | ||
All of | ||
ONLYOFFICE | <=7.3.0 | |
Linux Kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-48422 is considered a high severity vulnerability due to its potential to allow local users to escalate privileges.
To fix CVE-2022-48422, ensure that users do not run ONLYOFFICE Docs in directories where a malicious libgcc_s.so.1 may be present.
CVE-2022-48422 affects local users on certain Linux distributions using ONLYOFFICE Docs versions up to 7.3.
ONLYOFFICE Docs versions up to and including 7.3 are vulnerable to CVE-2022-48422.
CVE-2022-48422 requires local access to the affected system, making it not exploitable remotely.