Wacom Driver 6.3.46-1 for Windows and lower was discovered to contain an arbitrary file deletion vulnerability.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
https://lucabarile.github.io/Blog/blog.html | exploit third party advisory mitigation |
https://lucabarile.github.io/Blog/CVE-2022-38604/index.html | exploit third party advisory mitigation |
https://github.com/LucaBarile/CVE-2022-38604 | third party advisory exploit |