VYPR
Unrated severityNVD Advisory· Published Nov 17, 2022· Updated Apr 30, 2025

CVE-2022-38165

CVE-2022-38165

Description

Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbitrary locations on the F-Secure Policy Manager Server.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated arbitrary file write vulnerability in F-Secure Policy Manager allows attackers to write arbitrary content to arbitrary locations on the server.

Vulnerability

An arbitrary file write vulnerability exists in F-Secure Policy Manager through version 2022-08-10. An unauthenticated attacker can write a file with attacker-controlled contents to an arbitrary location on the Policy Manager Server. This issue was reported internally and no known exploit has been observed in the wild. The vulnerability affects the Policy Manager Server component, but the Policy Manager Proxy is not affected [1].

Exploitation

An unauthenticated attacker with network access to the F-Secure Policy Manager Server can send specially crafted requests to write a file with arbitrary contents to any path on the server file system. No authentication or prior access is required. The exact attack vector is not publicly detailed, but the advisory confirms that no authentication is needed to trigger the issue [1].

Impact

Successful exploitation allows an unauthenticated attacker to create or overwrite files anywhere on the F-Secure Policy Manager Server file system. This can lead to arbitrary code execution (e.g., by overwriting executables or configuration files), privilege escalation, or a complete compromise of the server's integrity and availability. The confidentiality of data may also be affected if the attacker can write files to sensitive locations [1].

Mitigation

WithSecure (formerly F-Secure) released Hotfix 4 to address this vulnerability. Administrators should download the hotfix from the WithSecure support portal and deploy it to the F-Secure Policy Manager. The hotfix and installation instructions are available at the official product support page [1]. No workaround is documented; applying the hotfix is the required remediation.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.