Lucene search

K
cvelistVulDBCVELIST:CVE-2022-3734
HistoryOct 28, 2022 - 12:00 a.m.

CVE-2022-3734 Redis on Windows dbghelp.dll uncontrolled search path

2022-10-2800:00:00
CWE-426
VulDB
www.cve.org
2
redis
windows
dbghelp.dll
uncontrolled search path
vulnerability
remote attack
disclosure
vdb-212416
port.

6.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

9.8 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.6%

A vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Program Files/Redis/dbghelp.dll. The manipulation leads to uncontrolled search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The identifier of this vulnerability is VDB-212416. NOTE: The official Redis release is not affected. This issue might affect an unofficial fork or port on Windows only.

CNA Affected

[
  {
    "vendor": "unspecified",
    "product": "Redis",
    "versions": [
      {
        "version": "n/a",
        "status": "affected"
      }
    ]
  }
]

6.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

9.8 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.6%

Related for CVELIST:CVE-2022-3734