RULE(RULE ID:336660)

Rule General Information
Release Date: 2022-06-21
Rule Name: VanDyke VShell Server Trigger Arbitrary Code Execution Vulnerability (CVE-2022-28054)
Severity:
CVE ID:
Rule Protection Details
Description: Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Others
Reference: https://www.vandyke.com/support/advisory/2022/02/remote-execution-via-triggers.html
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.vandyke.com/support/advisory/2022/02/remote-execution-via-triggers.html