CVE-2022-34866
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
20/07/2022
Last modified:
01/08/2022
Description
Passage Drive versions v1.4.0 to v1.5.1.0 and Passage Drive for Box version v1.0.0 contain an insufficient data verification vulnerability for interprocess communication. By running a malicious program, an arbitrary OS command may be executed with LocalSystem privilege of the Windows system where the product is running.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:yrl:passage_drive:*:*:*:*:*:*:*:* | 1.4.0 (including) | 1.5.1.0 (including) |
| cpe:2.3:a:yrl:passage_drive_for_box:1.0.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



