go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ChangingTec MegaServiSignAdapter - Improper Input Validation

TVN ID TVN-202212009
CVE ID CVE-2022-39060
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products ChangingTec MegaServiSignAdapter (Windows) v1.0.17.0823
Description ChangingTech MegaServiSignAdapter component has a vulnerability of improper input validation. An unauthenticated remote attacker can exploit this vulnerability to access and modify HKEY_CURRENT_USER subkey (ex: AutoRUN) in Registry where malicious scripts can be executed to take control of the system or to terminate the service.
Solution Update MegaServiSignAdapter (Windows) version to 1.0.22.1004
Credit Angelboy (DEVCORE Research Team)
Public Date 2023-01-31
Top