Improper Synchronization
CVE-2022-32645
Summary
In vow, there is a possible information disclosure due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494477; Issue ID: ALPS07494477.
- HIGH
- LOCAL
- NONE
- UNCHANGED
- NONE
- HIGH
- HIGH
- NONE
CWE-662 - Improper Synchronization
The software utilizes multiple threads or processes to allow temporary access to a shared resource that can only be exclusive to one process at a time, but it does not properly synchronize these actions, which might cause simultaneous accesses of this resource by multiple threads or processes.
References
Advisory Timeline
- Published