// For flags

CVE-2022-43701

Insecure directory permissions on installer files

Severity Score

7.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code.

*Credits: FalconCorruption, Intel
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-10-24 CVE Reserved
  • 2023-07-27 CVE Published
  • 2023-08-08 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-276: Incorrect Default Permissions
CAPEC
  • CAPEC-233: Privilege Escalation
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Arm
Search vendor "Arm"
Arm Compiler
Search vendor "Arm" for product "Arm Compiler"
>= 5.00 <= 5.06
Search vendor "Arm" for product "Arm Compiler" and version " >= 5.00 <= 5.06"
-
Affected
Arm
Search vendor "Arm"
Arm Compiler
Search vendor "Arm" for product "Arm Compiler"
>= 6.00 < 6.20
Search vendor "Arm" for product "Arm Compiler" and version " >= 6.00 < 6.20"
-
Affected
Arm
Search vendor "Arm"
Arm Compiler For Embedded Fusa
Search vendor "Arm" for product "Arm Compiler For Embedded Fusa"
6.16
Search vendor "Arm" for product "Arm Compiler For Embedded Fusa" and version "6.16"
lts
Affected
Arm
Search vendor "Arm"
Arm Compiler For Functional Safety
Search vendor "Arm" for product "Arm Compiler For Functional Safety"
6.6
Search vendor "Arm" for product "Arm Compiler For Functional Safety" and version "6.6"
-
Affected
Arm
Search vendor "Arm"
Arm Development Studio
Search vendor "Arm" for product "Arm Development Studio"
*-
Affected
Arm
Search vendor "Arm"
Arm Mobile Studio
Search vendor "Arm" for product "Arm Mobile Studio"
*-
Affected
Arm
Search vendor "Arm"
Ds Development Studio
Search vendor "Arm" for product "Ds Development Studio"
>= 5.0.0 <= 5.29.3
Search vendor "Arm" for product "Ds Development Studio" and version " >= 5.0.0 <= 5.29.3"
-
Affected
Arm
Search vendor "Arm"
Fast Models
Search vendor "Arm" for product "Fast Models"
*-
Affected
Arm
Search vendor "Arm"
Gnu Toolchain
Search vendor "Arm" for product "Gnu Toolchain"
*-
Affected
Arm
Search vendor "Arm"
Keil Mdk
Search vendor "Arm" for product "Keil Mdk"
*-
Affected
Arm
Search vendor "Arm"
Linaro Forge
Search vendor "Arm" for product "Linaro Forge"
< 22.1
Search vendor "Arm" for product "Linaro Forge" and version " < 22.1"
-
Affected
Arm
Search vendor "Arm"
Mbed Studio
Search vendor "Arm" for product "Mbed Studio"
*-
Affected