CVE-2022-45307: Chocolatey PHP

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Insecure permissions in Chocolatey PHP package v8.1.12 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\tools\php81 and all files located in that folder.

Affected products

  • Chocolatey Chocolatey PHP: up to and including 8.1.12

Published 2022-11-29. Last modified 2026-06-17.