NVD Vulnerability Detail
Search Exploit, PoC
CVE-2022-4991
Summary

Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by an unprivileged user on Windows. Tychon contains a privileged service that uses this OpenSSL component. A user who can place a specially-crafted openssl.cnf file at an appropriate path may be able to achieve arbitrary code execution with SYSTEM privileges.

Publication Date June 2, 2026, 2:16 a.m.
Registration Date June 2, 2026, 4:17 a.m.
Last Update June 2, 2026, 3:02 a.m.
Related information, measures and tools
Common Vulnerabilities List