CVE-2022-34687 is a high-severity Remote Code Execution vulnerability affecting Microsoft Azure RTOS GUIX Studio. An attacker could exploit this by tricking a user into opening a specially crafted file, leading to complete compromise of confidentiality, integrity, and availability on the affected system. While there is no public exploit code or active exploitation reported, its CVSS score of 7.8 and inclusion in a BleepingComputer article highlight its potential impact and warrant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.0.0, < 6.1.12.0CPE match | cpe:2.3:a:microsoft:azure_rtos_guix_studio:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_real_time_operating_system_guix_studio:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.