peter bassill · operator
$ cve CVE-2022-32272 JSON

CVE-2022-32272 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 9.6% (pctl 95)

Patch early

A public exploit exists.

Description

OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access control, resulting in privilege escalation.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS9.55% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-269
On CISA KEVno
Public exploityes
Published2022-06-09
Last modified2026-06-17

Affected (1)

VendorProduct
opswatmetadefender

Public exploits

SourceTitleDate
exploit-dbOPSWAT Metadefender Core - Privilege Escalation2023-03-28

References

→ the Explorer  ·  watch your stack  ·  NVD