CVE-2022-27595

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Dec 19, 2024
CWE ID 427

Summary

CVE-2022-27595 is a newly disclosed vulnerability affecting QVPN Device Client. This insecure library loading issue poses a risk for local attackers who have obtained user access, enabling them to execute unauthorized code or commands on the affected system. This vulnerability has been addressed in recent updates to QVPN Windows, including version 2.0.0.1316 and later, as well as version 2.0.0.1310 and later.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share