Vulnerability CVE-2022-39060


Published: 2023-01-31

Description:
ChangingTech MegaServiSignAdapter component has a vulnerability of improper input validation. An unauthenticated remote attacker can exploit this vulnerability to access and modify HKEY_CURRENT_USER subkey (ex: AutoRUN) in Registry where malicious scripts can be executed to take control of the system or to terminate the service.

Type:

CWE-20

(Improper Input Validation)

 References:
https://www.twcert.org.tw/tw/cp-132-6887-6ed4f-1.html

Copyright 2026, cxsecurity.com

 

Back to Top