cbcvebase.
CVE-2022-22582
published 2023-02-27

CVE-2022-22582: A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update…

PriorityP341medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
17.71%
96.8th percentile
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5, macOS Monterey 12.3. A local user may be able to write arbitrary files.

Affected

9 ranges
VendorProductVersion rangeFixed in
applemac_os_x
applemacos>= 11.0 < 11.6.511.6.5
applemacos>= 12.0.0 < 12.312.3
applemacos>= unspecified < 12.312.3
applemacos>= unspecified < 20222022
applemacos>= unspecified < 11.611.6
applemacos_big_sur
applemacos_monterey
applesecurity_update_2022-003_catalina
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.