Code Injection in Simba Amazon Redshift ODBC Driver - CVE-2022-29972
Published: May 9, 2022
Vulnerability details
The vulnerability allows a local user to escalate privileges within the application.
The vulnerability exists due to argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift ODBC Driver and involves improper validation of authentication tokens. A local user can escalate privileges within the affected application.
Affected software
Microsoft Integration Runtime
How to mitigate CVE-2022-29972
Microsoft Integration Runtime - update to 5.15.8094.1