CVE-2022-43703

Published Jul 27, 2023

Last updated 9 months ago

Overview

Description
An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under control of an attacker being loaded or executed instead of the intended files.
Source
arm-security@arm.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
CWE-427
arm-security@arm.com
CWE-427

Social media

Hype score
Not currently trending

Configurations