Vulnerability Details CVE-2022-37172
Incorrect access control in the install directory (C:\msys64) of Msys2 v20220603 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 10.4%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2022-37172
-
-
cpe:2.3:a:msys2:msys2:20220603