CVE-2022-22996 HIGH

CVE-2022-22996: SanDisk Professional G-RAID 4/8 Software Utility, Privilege Escalation

Vendor Sandisk Professional
Product G-RAID 4/8 Software Utility
Weakness CWE-427
Published March 30, 2022
Last update August 3, 2024

CVSS base score

7.8/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The G-RAID 4/8 Software Utility setups for Windows were affected by a DLL hijacking vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the system user.

Key dates

02Disclosure timeline

March 30, 2022 CVE published
August 3, 2024 Record updated