CRITICAL 9.8 Microsoft

CVE-2022-3515

A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application for example a malicious S/MIME attachment.

Microsoft Security Update 2023-Jan: A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application for example a malicious S/MIME attachment.

Affected Products

References

Published: 2023-01-10 · Source: Microsoft · Feed updated: 2026-08-04
This critical severity vulnerability with a CVSS score of 9.8 was published on 2023-01-10 via Microsoft. Affected: cm1 libksba 1.3.5-5 on CBL Mariner 1.0, cm1 gnupg2 2.2.20-4 on CBL Mariner 1.0, cbl2 gnupg2 2.4.0-1 on CBL Mariner 2.0.

Risk Timeline

CVE Disclosed2023-01-10 · 1301 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2022-4338An integer underflow in Organization Specific TLV was found in various versions CRITICAL9.8
CVE-2022-41903 PoCInteger overflow in `git archive` `git log --format` leading to RCE in gitCRITICAL9.8
CVE-2022-4337An out-of-bounds read in Organization Specific TLV was found in various versionsCRITICAL9.8
CVE-2022-36760Apache HTTP Server: mod_proxy_ajp Possible request smugglingCRITICAL9.0
CVE-2022-2196Speculative execution attacks in KVM VMXHIGH8.8
CVE-2023-0051Heap-based Buffer Overflow in vim/vimHIGH7.8
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.