Input validation error in Photo Station - CVE-2022-27593

 

Input validation error in Photo Station - CVE-2022-27593

Published: September 6, 2022 / Updated: October 21, 2022


Vulnerability identifier: #VU66993
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-27593
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to unspecified vulnerability. A remote non-authenticated attacker can send a specially crafted request to the affected system and execute arbitrary code.

Note, the vulnerability is being actively exploited in the wild by the DeadBolt ransomware.


Affected software

Photo Station

How to mitigate CVE-2022-27593

Install updates from vendor's website.

Photo Station - addressed in versions 5.2.14, 5.4.15, 5.7.18, 6.0.22, 6.1.2

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins