Logo
vulnerabilityCVE-2022-26488
Name
CVE-2022-26488
Source
NVD ( link)Debian ( link)
Description
In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may allow a local attacker to add user-writable directories to the system search path. To exploit, an administrator must have installed Python for all users and enabled PATH entries. A non-administrative user can trigger a repair that incorrectly adds user-writable paths into PATH, enabling search-path hijacking of other users and system services. This affects Python (CPython) through 3.7.12, 3.8.x through 3.8.12, 3.9.x through 3.9.10, and 3.10.x through 3.10.2.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
python3
False Positive

Vulnerability Ratings#


7
CVSSv31
4.4
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.12.13
Not Affected
buildroot
master
3.14.6
Not Affected
openwrt
master
3.14.5-r1
Not Affected
openwrt
openwrt-25.12
3.13.9-r3
Not Affected
yocto
kirkstone
3.10.20
Not Affected
yocto
master
3.14.6
Not Affected