KA005596
by Arm
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-43703 | Hig | 0.51 | 7.8 | 0.00 | Jul 27, 2023 | An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under control of an attacker being loaded or executed instead of the intended files. | ||
| CVE-2022-43702 | Hig | 0.51 | 7.8 | 0.00 | Jul 27, 2023 | When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code. |
- risk 0.51cvss 7.8epss 0.00
An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under control of an attacker being loaded or executed instead of the intended files.
- risk 0.51cvss 7.8epss 0.00
When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code.