Local Privilege Escalation Vulnerability in XAMPP Installer

Local Privilege Escalation Vulnerability in XAMPP Installer

CVE-2022-47637 · MEDIUM Severity

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory. Common use cases execute files under C:\xampp with administrative privileges.

Learn more about our User Device Pen Test.