VYPR
Unrated severityNVD Advisory· Published Jan 31, 2023· Updated Mar 27, 2025

ChangingTec MegaServiSignAdapter - Improper Input Validation

CVE-2022-39060

Description

ChangingTech MegaServiSignAdapter component has a vulnerability of improper input validation. An unauthenticated remote attacker can exploit this vulnerability to access and modify HKEY_CURRENT_USER subkey (ex: AutoRUN) in Registry where malicious scripts can be executed to take control of the system or to terminate the service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated remote attackers can exploit improper input validation in ChangingTech MegaServiSignAdapter to modify registry keys and execute malicious scripts.

Vulnerability

The ChangingTech MegaServiSignAdapter component on Windows version 1.0.17.0823 suffers from an improper input validation vulnerability [1]. The specific functionality does not filter or validate parameter values passed to it, allowing an unauthenticated remote attacker to write to HKEY_CURRENT_USER subkeys, such as AutoRUN [1]. This affects the MegaServiSignAdapter Windows component up to version 1.0.17.0823 [1].

Exploitation

No authentication or user interaction is required; the attacker only needs network access to the vulnerable system [1]. By sending a crafted request with malicious input to the unvalidated parameter, the attacker can write arbitrary registry entries under HKEY_CURRENT_USER [1]. This can be done remotely without any prior privileges [1].

Impact

Successful exploitation allows the attacker to execute malicious scripts via the registry key (e.g., AutoRUN), potentially gaining control of the system or terminating critical services [1]. The CVSS v3.1 score is 9.8 (Critical), reflecting full compromise of confidentiality, integrity, and availability [1].

Mitigation

The vendor released a fix in version v1.0.22.1004 of MegaServiSignAdapter for Windows [1]. Users should update to this patched version to remediate the vulnerability. No workarounds are mentioned in the reference.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.