CVE Feed

    Dashboard / CVE / CVE-2022-48199

    CVE-2022-48199

    SoftPerfect NetWorx 7.1.1 on Windows allows an attacker to execute a malicious binary with potentially higher privileges via a low-privileged user account that abuses the Notifications function. The Notifications function allows for arbitrary binary execution and can be modified by any user. The resulting binary execution will occur in the context of any user running NetWorx. If an attacker modifies the Notifications function to execute a malicious binary, the binary will be executed by every user running NetWorx on that system.

    Published:Jan 24, 2023
    Last Modified:Apr 2, 2025
    EPS:Jan 24, 2023
    EPSS Score:0.00624
    CVSS Score:8.8

    Affected Products

    Vendor
    Microsoft
    Product
    Windows
    Vendor
    Softperfect
    Product
    Networx

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High