CVE-2022-36271

Outbyte PC Repair Installation File 1.7.112.7856 is vulnerable to Dll Hijacking. iertutil.dll is missing so an attacker can use a malicious dll with same name and can get admin privileges.
References
Link Resource
http://outbyte.com Vendor Advisory
https://github.com/SaumyajeetDas/POC-of-CVE-2022-36271 Exploit Third Party Advisory
http://outbyte.com Vendor Advisory
https://github.com/SaumyajeetDas/POC-of-CVE-2022-36271 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:outbyte:pc_repair:1.7.112.7856:*:*:*:*:*:*:*

History

21 Nov 2024, 07:12

Type Values Removed Values Added
References () http://outbyte.com - Vendor Advisory () http://outbyte.com - Vendor Advisory
References () https://github.com/SaumyajeetDas/POC-of-CVE-2022-36271 - Exploit, Third Party Advisory () https://github.com/SaumyajeetDas/POC-of-CVE-2022-36271 - Exploit, Third Party Advisory

12 Sep 2022, 13:30

Type Values Removed Values Added
References (MISC) https://github.com/SaumyajeetDas/POC-of-CVE-2022-36271 - (MISC) https://github.com/SaumyajeetDas/POC-of-CVE-2022-36271 - Exploit, Third Party Advisory
References (MISC) http://outbyte.com - (MISC) http://outbyte.com - Vendor Advisory
CWE CWE-427
CPE cpe:2.3:a:outbyte:pc_repair:1.7.112.7856:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

07 Sep 2022, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-07 14:15

Updated : 2024-11-21 07:12


NVD link : CVE-2022-36271

Mitre link : CVE-2022-36271

CVE.ORG link : CVE-2022-36271


JSON object : View

Products Affected

outbyte

  • pc_repair
CWE
CWE-427

Uncontrolled Search Path Element