CVE-2022-32272
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 9.3%
from disclosure to weapon292 days
Published on NVDJun 9
1st PoC+292d
exploitation probability
9.3%top 5% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access control, resulting in privilege escalation.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/51113unverifiedcve_referencepacketstormsecurity.com/files/171549/OPSWAT-Metadefender-Core-4.21.1-Privilege-Escalation.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/171549/OPSWAT-Metadefender-Core-4.21.1-Privilege-Escalation.htmlhttps://docs.opswat.com/mdcore/release-noteshttps://docs.opswat.com/mdemail/release-noteshttps://docs.opswat.com/mdemail/release-notes/version-5-6-1https://docs.opswat.com/mdicap/release-noteshttps://docs.opswat.com/mdicap/release-notes/version-4-12-1https://opswat.com