CRITICAL

CVE-2022-24562

CVSS v3

9.8

CRITICAL

EPSS Score

49.2%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.

Technical details

Published
6/16/2022

Frequently asked questions

What is CVE-2022-24562?

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.

Is CVE-2022-24562 actively exploited?

Active exploitation of CVE-2022-24562 has not been confirmed. The EPSS score is 49.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-24562?

CVE-2022-24562 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2022-24562 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.