CVE-2022-4991 UNKNOWN

CVE-2022-4991

Published: 2026-06-01

Description

Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by an unprivileged user on Windows. Tychon contains a privileged service that uses this OpenSSL component. A user who can place a specially-crafted openssl.cnf file at an appropriate path may be able to achieve arbitrary code execution with SYSTEM privileges.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…