CVE-2022-34392

CVE-2022-34392

SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An authenticated non-admin user can be able to obtain the refresh token and that leads to reuse the access token and fetch sensitive information.

Source: CVE-2022-34392

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다