CVE-2022-22262 - CVE House
Back to Database
Status published High CVE-2022-22262

ASUS Armoury Crate & Aura Creator Installer之ROG Live Service - Improper Link Resolution Before File Access

Vulnerability Description

ROG Live Service’s function for deleting temp files created by installation has an improper link resolution before file access vulnerability. Since this function does not validate the path before deletion, an unauthenticated local attacker can create an unexpected symbolic link to system file path, to delete arbitrary system files and disrupt system service.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-22262

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Armoury Crate & Aura Creator Installer (ROG Live Service)
Vulnerable Versions:
1.2.18.0

Timeline

Official Publish: March 1st, 2022
Last Modified: September 17th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Weaknesses (CWE)