CVE-2022-4991: Tychon
High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.
Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by an unprivileged user on Windows. Tychon contains a privileged service that uses this OpenSSL component. A user who can place a specially-crafted openssl.cnf file at an appropriate path may be able to achieve arbitrary code execution with SYSTEM privileges.
Affected products
- Tychon Tychon: before 1.7.857.82 (fixed in 1.7.857.82)
Published 2026-06-01. Last modified 2026-07-22.