IM
IronMonkey Threat Research

CVE-2022-1467 CRITICAL

Published: 2022-05-23 | Last Modified: 2024-11-21 | Status: Modified

Description

Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is possible to manipulate the Windows OS language bar to launch an OS command prompt, resulting in a context-escape from application into OS.

Additional Descriptions (1)

El Sistema Operativo Windows puede configurarse para superponer "language bar" sobre cualquier aplicación. Cuando esta funcionalidad del SO está habilitada, la UI de la barra de lenguaje del SO será visible en el navegador junto a las aplicaciones AVEVA InTouch Access Anywhere y Plant SCADA Access Anywhere. Es posible manipular la barra de lenguaje del SO de Windows para lanzar un prompt de comando del SO, resultando en un escape de contexto de la aplicación al SO

CVSS Metrics

Base Score: 9.9 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.1

Impact Score: 6.0

Base Score: 8.5 (HIGH)

AV:N/AC:M/Au:S/C:C/I:C/A:C

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationSINGLE
Confidentiality ImpactCOMPLETE
Integrity ImpactCOMPLETE
Availability ImpactCOMPLETE

Source: [email protected]

Type: Primary

Exploitability Score: 6.8

Impact Score: 10.0

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-668

Affected Products

Vendor Product Version Update Type
aveva intouch_access_anywhere * <built-in method update of dict object at 0x7e60eb2693c0> Application
aveva plant_scada_access_anywhere * <built-in method update of dict object at 0x7e60eb26bf40> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:aveva:intouch_access_anywhere:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:aveva:plant_scada_access_anywhere:*:*:*:*:*:*:*:*

References

Notification
Message here