CVE-2022-45307: Chocolatey PHP
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Insecure permissions in Chocolatey PHP package v8.1.12 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\tools\php81 and all files located in that folder.
Affected products
- Chocolatey Chocolatey PHP: up to and including 8.1.12
Published 2022-11-29. Last modified 2026-06-17.