Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2022-21675

9.9 · CRITICAL
Published Jan 12, 2022 bytecode_viewer_project CWE-22 EPSS 2.54% (84th pctl)

Overview

CVE-2022-21675 is a critical-severity vulnerability affecting bytecode_viewer_project bytecode_viewer. It was published on January 12, 2022 and has a CVSS 3.1 base score of 9.9 (CRITICAL).

This vulnerability has a CVSS 3.1 base score of 9.9, rated CRITICAL. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

Technical Description

Bytecode Viewer (BCV) is a Java/Android reverse engineering suite. Versions of the package prior to 2.11.0 are vulnerable to Arbitrary File Write via Archive Extraction (AKA "Zip Slip"). The vulnerability is exploited using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe). The Zip Slip vulnerability can affect numerous archive formats, including zip, jar, tar, war, cpio, apk, rar and 7z. The attacker can then overwrite executable files and either invoke them remotely or wait for the system or user to call them, thus achieving remote command execution on the victim’s machine. The impact of a Zip Slip vulnerability would allow an attacker to create or overwrite existing files on the filesystem. In the context of a web application, a web shell could be placed within the application directory to achieve code execution. All users should upgrade to BCV v2.11.0 when possible to receive a patch. There are no recommended workarounds aside from upgrading

Remediation

Check the references section for vendor advisories and patches from bytecode_viewer_project. Update bytecode_viewer to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
bytecode_viewer_project bytecode_viewer >= 2.10.16, < 2.11.0 Affected

Frequently Asked Questions

What is CVE-2022-21675?

CVE-2022-21675 is a critical-severity vulnerability affecting bytecode_viewer_project bytecode_viewer. It was published on January 12, 2022 and has a CVSS 3.1 base score of 9.9 (CRITICAL).

How severe is CVE-2022-21675?

This vulnerability has a CVSS 3.1 base score of 9.9, rated CRITICAL. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2022-21675?

Check the references section for vendor advisories and patches from bytecode_viewer_project. Update bytecode_viewer to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2022-21675?

CyberStrike's AI-powered security agents can automatically detect CVE-2022-21675 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.