The vulnerability causing from insufficient verification procedures for downloaded files during WebCube update. Remote attackers can bypass this verification logic to update both digitally signed and unauthorized files, enabling remote code execution.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: krcert

Published: 2022-08-17T20:23:03

Updated: 2022-08-17T20:23:03

Reserved: 2022-01-19T00:00:00


Link: CVE-2022-23764

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-08-17T21:15:08.847

Modified: 2022-08-19T12:47:46.317


Link: CVE-2022-23764

JSON object: View

cve-icon Redhat Information

No data.

CWE