Skip to main content
Skip to main content
Published Feb 10, 2023 | Updated Mar 23, 2023

Exploit:Python/CVE-2022-47986.A

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

This is the detection for python script that exploits CVE-2022-47986, a vulnerability in IBM Aspera Faspex. Attackers attempting to take advantage of the vulnerability could run arbitrary code on the device, caused by a YAML deserialization flaw. 

  • Remove any affected devices from the network and thoroughly investigate for any signs of a breach. 
  • If you have cloud-delivered protection, your device gets the latest defenses against new and unknown threats. If you don't have this feature turned on, update your antimalware definitions and run a full scan to remove this threat. 

Apply the following mitigations to reduce the impact of this threat: 

  • A patch is available for CVE-2022-47986. Administrators should upgrade to version 4.4.2 PL (Patch Level) 2 to address the obsolete API call. 

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help. 

Follow us