CVE-2022-27595
An insecure library loading vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local attackers who have gained user access to execute unauthorized code or commands.
We have already fixed the vulnerability in the following versions: QVPN Windows 2.0.0.1316 and later QVPN Windows 2.0.0.1310 and later
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Base score: 7.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.18%
- Percentile among all scored CVEs: 7
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Primary impact
T1059Command and Scripting Interpreterexecution80 % - Secondary impact
T1574.007Path Interception by PATH Environment Variablestealth · execution75 %
AV:L + PR:L sin interacción: escalada local. CWE-427 (insecure library loading) y ejecución de código no autorizado confirman T1059 + T1574.007 (DLL hijacking).
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
CWEs
- CWE-427
References
Raw JSON (NVD)
Show
{
"id": "CVE-2022-27595",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-27595",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-12-20T16:59:39.320965Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@qnapsecurity.com.tw",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "security@qnapsecurity.com.tw",
"affectedData": [
{
"vendor": "QNAP Systems Inc.",
"product": "QVPN Windows",
"versions": [
{
"status": "affected",
"version": "2.0.x",
"lessThan": "2.0.0.1316",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.0.x",
"lessThan": "2.0.0.1310",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-12-19T02:15:21.300",
"references": [
{
"url": "https://www.qnap.com/en/security-advisory/qsa-23-04",
"tags": [
"Vendor Advisory"
],
"source": "security@qnapsecurity.com.tw"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@qnapsecurity.com.tw",
"description": [
{
"lang": "en",
"value": "CWE-427"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An insecure library loading vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local attackers who have gained user access to execute unauthorized code or commands.\n\nWe have already fixed the vulnerability in the following versions:\nQVPN Windows 2.0.0.1316 and later\nQVPN Windows 2.0.0.1310 and later"
},
{
"lang": "es",
"value": "Se ha informado de una vulnerabilidad de carga de librerías inseguras que afecta a QVPN Device Client. Si se explota, la vulnerabilidad podría permitir que atacantes locales que hayan obtenido acceso de usuario ejecuten código o comandos no autorizados. Ya hemos corregido la vulnerabilidad en las siguientes versiones: QVPN Windows 2.0.0.1316 y posteriores QVPN Windows 2.0.0.1310 y posteriores"
}
],
"lastModified": "2026-06-17T04:37:19.710",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:qvpn:*:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "714F4470-FD09-4E02-B85E-814FE858851F",
"versionEndExcluding": "2.0.0.1316"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@qnapsecurity.com.tw"
}