Junglewise Threat Intelligence

CVE-2022-4991: Tychon privilege escalation via insecure OPENSSLDIR path

CVE-2022-4991 · Severity: info · Published 2026-06-01

Executive brief

Tychon, an endpoint security and management platform, contains a vulnerability that could allow a standard user to take full control of a Windows computer. By placing a malicious configuration file in a specific folder that the software incorrectly trusts, an attacker can trick a high-privilege background service into running unauthorized code. This could lead to a complete system takeover, allowing the attacker to bypass security controls or access sensitive data.

Technical details

Tychon includes an OpenSSL component configured with an OPENSSLDIR variable pointing to a subdirectory that is writable by unprivileged users on Windows. Because Tychon runs a privileged service using this component, it will attempt to load configuration files from this insecure path. An attacker with local access can place a specially crafted 'openssl.cnf' file in that directory to trigger arbitrary code execution. When the privileged service loads the malicious configuration, the code executes with SYSTEM privileges. This issue is resolved in Tychon version 1.7.857.82.

Affected products

  • Tychon Tychon Endpoint Before 1.7.857.82

Timeline

  • 2022-03-10: other: Vendor notified
  • 2022-04-27: other: Vendor statement issued
  • 2022-04-28: disclosed: Initial public release of vulnerability note
  • 2022-04-28: patched: Fix released in version 1.7.857.82
  • 2026-06-01: advisory: NVD publication date

References