CVE-2022-34866

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
20/07/2022
Last modified:
01/08/2022

Description

Passage Drive versions v1.4.0 to v1.5.1.0 and Passage Drive for Box version v1.0.0 contain an insufficient data verification vulnerability for interprocess communication. By running a malicious program, an arbitrary OS command may be executed with LocalSystem privilege of the Windows system where the product is running.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:yrl:passage_drive:*:*:*:*:*:*:*:* 1.4.0 (including) 1.5.1.0 (including)
cpe:2.3:a:yrl:passage_drive_for_box:1.0.0:*:*:*:*:*:*:*