PT-2022-17918 · Unknown+1 · Miniconda3+1

CVE-2022-26526

·

Published

2022-03-17

·

Updated

2024-03-06

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Anaconda3 versions through 2021.11.0.0 Miniconda3 versions through 4.11.0.0
Description The issue allows local users to gain privileges by placing a Trojan horse file into a world-writable directory under %PROGRAMDATA% that is added to the system PATH environment variable. This problem can only occur in non-default installations where the product is installed for all users and the system PATH is changed.
Recommendations For Anaconda3 versions through 2021.11.0.0, avoid installing the product for all users or modifying the system PATH to prevent exploitation. For Miniconda3 versions through 4.11.0.0, consider restricting access to the world-writable directory under %PROGRAMDATA% until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MINICONDA-2022-26526
CVE-2022-26526

Affected Products

Anaconda3
Miniconda3