Arbitrary Code Execution via SMB and AFP File Writing Vulnerability

Arbitrary Code Execution via SMB and AFP File Writing Vulnerability

CVE-2022-22995 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.

Learn more about our Web Application Penetration Testing UK.