Lucene search

K
cvelistABBCVELIST:CVE-2022-26057
HistoryJun 15, 2022 - 6:47 p.m.

CVE-2022-26057 Mint WorkBench Link Following Local Privilege Escalation Vulnerability

2022-06-1518:47:01
CWE-269
ABB
www.cve.org
6
mint workbench
vulnerability
local privilege escalation

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0

Percentile

12.6%

Vulnerabilities in the Mint WorkBench allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Mint WorkBench installer file allows a low-privileged user to run a “repair” operation on the product

CNA Affected

[
  {
    "product": "Mint WorkBench",
    "vendor": "ABB",
    "versions": [
      {
        "lessThanOrEqual": "5866",
        "status": "affected",
        "version": "build",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVELIST:CVE-2022-26057