peter bassill · operator
$ cve CVE-2022-4510 JSON

CVE-2022-4510 EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 22% (pctl 98)

Patch early

A public exploit exists.

Description

A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By crafting a malicious PFS filesystem file, an attacker can get binwalk's PFS extractor to extract files at arbitrary locations when binwalk is run in extraction mode (-e option). Remote code execution can be achieved by building a PFS filesystem that, upon extraction, would extract a malicious binwalk module into the folder .config/binwalk/plugins. This vulnerability is associated with program files src/binwalk/plugins/unpfs.py. This issue affects binwalk from 2.1.2b through 2.3.3 included.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS22.01% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2023-01-26
Last modified2026-06-17

Affected (1)

VendorProduct
microsoftbinwalk

Public exploits

SourceTitleDate
exploit-dbBinwalk v2.3.2 - Remote Command Execution (RCE)2023-04-05

References

→ the Explorer  ·  watch your stack  ·  NVD