CVE-2022-27905

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
27/04/2022
Last modified:
09/05/2022

Description

In ControlUp Real-Time Agent before 8.6, an unquoted path can result in privilege escalation. An attacker would require write permissions to the root level of the OS drive (C:\) to exploit this.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:controlup:controlup:*:*:*:*:*:*:*:* 8.6 (excluding)


References to Advisories, Solutions, and Tools