CVE-2022-22996

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
30/03/2022
Last modified:
07/04/2022

Description

The G-RAID 4/8 Software Utility setups for Windows were affected by a DLL hijacking vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the system user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:westerndigital:sandisk_professional_g-raid_4\/8_software_utility:*:*:*:*:*:windows:*:* 300520006-2 (excluding)
cpe:2.3:a:westerndigital:sandisk_professional_g-raid_4\/8_software_utility_driver:*:*:*:*:*:windows:*:* 6.2.0.16-2 (excluding)