cve/2022/CVE-2022-24562.md
2024-06-18 02:51:15 +02:00

967 B

CVE-2022-24562

Description

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.

POC

Reference

Github