VulnerabilityModified
CVE-2022-45304
Insecure permissions in Chocolatey Cmder package v1.3.20 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\Cmder and all files located in that folder.
MEDIUM 4.3EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
Insecure permissions in Chocolatey Cmder package v1.3.20 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\Cmder and all files located in that folder.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- chocolatey/chocolatey cmder
- Source
- cve@mitre.org
References
- https://github.com/ycdxsb/Vuln/blob/main/cmder-weak-permission-vuln/cmder-weak-permission-vuln.mdBroken Link, Third Party Advisory
- https://github.com/ycdxsb/Vuln/blob/main/cmder-weak-permission-vuln/cmder-weak-permission-vuln.mdBroken Link, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.