Security Advisory

CVE-2022-34866

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-07-20 06:15:28
Last updated 2024-08-03 09:22:10
Assigner jpcert
State PUBLISHED

Description

Passage Drive versions v1.4.0 to v1.5.1.0 and Passage Drive for Box version v1.0.0 contain an insufficient data verification vulnerability for interprocess communication. By running a malicious program, an arbitrary OS command may be executed with LocalSystem privilege of the Windows system where the product is running.