#VU66328 Code Injection in Windows Server and Windows - CVE-2022-30194
Published: August 10, 2022 / Updated: August 18, 2022
Windows Server
Windows
Microsoft
Description
The vulnerability allows a remote attacker to execute arbitrary untrusted scripts.
The vulnerability exists due to the way certain image file types, such as SVG, are processed by Microsoft Windows. A remote attacker can trick the victim to open a specially crafted page or file and execute arbitrary code in the context of the current process.