CVE-2022-3664 is a critical heap-based buffer overflow vulnerability found in the AP4_BitStream::WriteBytes function within the avcinfo component of Axiomatic Bento4. This flaw, identified as VDB-212004, allows for remote attacks and affects axiosys bento4 products. The vulnerability carries a CVSS score of 7.8 (High), indicating a high potential for impact on confidentiality, integrity, and availability, with a low attack complexity and requiring user interaction. While the exploit has been publicly disclosed, its EPSS score is very low, suggesting a minimal likelihood of exploitation in the wild. Currently, there is no evidence of active exploitation, and no exploit modules are available in Metasploit, Nuclei, or ExploitDB. Furthermore, there is no community discussion or media coverage surrounding this CVE, indicating a lack of widespread attention despite the public disclosure of exploit details.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6.0-639CPE matchmatch criteria | cpe:2.3:a:axiosys:bento4:1.6.0-639:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.