CVE-2022-2332 – Honeywell SoftMaster Incorrect Permission Assignment for Critical Resource
https://notcve.org/view.php?id=CVE-2022-2332
A local unprivileged attacker may escalate to administrator privileges in Honeywell SoftMaster version 4.51, due to insecure permission assignment. Un atacante local no privilegiado puede escalar a privilegios de administrador en Honeywell SoftMaster versión 4.51, debido a una asignación no segura de permisos • https://www.cisa.gov/uscert/ics/advisories/icsa-22-256-02 https://www.security.honeywell.com/-/media/Security/Resources/PDF/Product-Warranty/Security_Notification_SN_2019-09-13-02_V4-pdf.pdf • CWE-732: Incorrect Permission Assignment for Critical Resource •
CVE-2022-2333 – Honeywell SoftMaster Uncontrolled Search Path Element
https://notcve.org/view.php?id=CVE-2022-2333
If an attacker manages to trick a valid user into loading a malicious DLL, the attacker may be able to achieve code execution in Honeywell SoftMaster version 4.51 application’s context and permissions. Si un atacante logra engañar a un usuario válido para que cargue una DLL maliciosa, el atacante puede lograr la ejecución de código en el contexto y los permisos de la aplicación Honeywell SoftMaster versión 4.51 • https://github.com/shirouQwQ/CVE-2022-2333 https://www.cisa.gov/uscert/ics/advisories/icsa-22-256-02 https://www.security.honeywell.com/-/media/Security/Resources/PDF/Product-Warranty/Security_Notification_SN_2019-09-13-02_V4-pdf.pdf • CWE-427: Uncontrolled Search Path Element •