SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-2188

Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory.

MEDIUM 5.5EPSS 0.15%

Does this matter?

Lower severity and a low EPSS score (0.15%). Track it; it rarely justifies an emergency change on its own.

Description

Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory. This can lead to a denial-of-service attack on the DXL Broker.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.15% probability · 5th percentile
CISA KEV
Not listed
Weakness
CWE-732
Affected
mcafee/data exchange layer
Source
trellixpsirt@trellix.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.