go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ASUS Armoury Crate Service - Arbitrary File Creation via Elevation of Privilege Flaw

TVN ID TVN-202209001
CVE ID CVE-2022-38699
CVSS 5.9 (Medium)
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Affected Products Armoury Crate Service V5.1.5.0
Description Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A physical attacker with general user privilege can modify the log file property to a symbolic link that points to arbitrary system file, causing the logging function to overwrite the system file and disrupt the system.
Solution Update Armoury Crate Service version to V5.2.10.0
Credit ASUS
Public Date 2022-09-15
Top