Wacom Driver 6.3.46-1 for Windows was discovered to contain an arbitrary file write vulnerability via the component \Wacom\Wacom_Tablet.exe.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
https://lucabarile.github.io/Blog/blog.html | mitigation third party advisory exploit |
https://lucabarile.github.io/Blog/CVE-2022-43293/index.html | mitigation third party advisory exploit |
https://github.com/LucaBarile/CVE-2022-43293 | third party advisory exploit |
https://cdn.wacom.com/u/productsupport/drivers/win/professional/releasenotes/Windows_6.4.2-1.html |