CVE-2022-24562

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
16/06/2022
Last modified:
07/11/2023

Description

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:iobit:iotransfer:4.3.1.1561:*:*:*:*:*:*:*