CVE-2022-38699

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
28/09/2022
Last modified:
30/09/2022

Description

Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A physical attacker with general user privilege can modify the log file property to a symbolic link that points to arbitrary system file, causing the logging function to overwrite the system file and disrupt the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:asus:armoury_crate_service:*:*:*:*:*:*:*:* 5.2.10.0 (excluding)


References to Advisories, Solutions, and Tools