CVE-2022-4991
Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by an unprivileged use
CVSS
7.4
High
EPSS
0.3%
p17
KEV
—
Exploit Today
5
0-100
Published: Jun 1, 2026 · Last modified: Jul 22, 2026
0.3%EPSS · 30 days0.3%
2026-08-012026-08-28
Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by an unprivileged user on Windows. Tychon contains a privileged service that uses this OpenSSL component. A user who can place a specially-crafted openssl.cnf file at an appropriate path may be able to achieve arbitrary code execution with SYSTEM privileges.
No related CVEs by CWE or product.