CVE-2022-27438

HIGHCVSS 8.1/10EPSS 2.38%

Last modified

CVE-2022-27438 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.. EPSS estimates a 2.38% chance of exploitation in the next 30 days.

Description

Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.

Metrics

CVSS 3.1
8.1/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
2.38%

81.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CaphyonAdvanced Installer< 19.4
3cxCall Flow Designer18.2.13
3cxCrm Template Generator2.1.23
BoomBoomtv Streamer Portal2.2.1
CodesectorDirect Folders4.0
CodesectorTeracopy3.8.5
EmeditorEmeditor21.3.0
FlamoryFlamory4.2.19.0
FreesnippingtoolFree Snipping Tool5.6.0.0
FxsoundFxsound1.1.12.0
GainedgeBetter Explorer2020.3.15.1304
GamecasterGamecaster4.0.2109.2802
GetmailbirdMailbird2.9.50.0
GuzogoGuzogo1.0.5.0
HoneygainHoneygain0.10.7.0
JkiVi Package Manager21.1.2754
JpsoftTake Command28.2.18
KrylackArchive Password Recovery3.70.69
KrylackAsterisks Password Decryptor3.31.107
KrylackBurning Suite1.20.05
KrylackRar Password Recovery3.70.69
KrylackVolume Serial Number Editor2.02.34
KrylackZip Password Recovery3.70.69
MoonsoftwarePassword Agent20.10.1
NefariusScptoolkit1.6.238.16010
PlagiarismcheckerxPlagiarism Checker X8.0.6
Prusa3dPrusaslicer2.4.2
RealdefenseMycleanid4.1.4
RealdefenseMycleanpc4.0.2
RealdefenseMypasslock1.9.6
RovioAngry Birds Space1.4.1
RovioBad Piggies1.3.0
SynapticsDisplaylink Usb Graphics< 10.3.6400.0
Urban-VpnUrban Vpn2.2.5
VigemVigembus Driver1.16.116
VpnhoodVpnhood2.4.299
VrdesktopVirtual Desktop Streamer1.20.16
XsplitXsplit Express Video Editor3.0.2001.801
RstinstrumentsVw0420 Firmware1.33.0
RstinstrumentsInclinalysis Digital Inclinometer2.48.9
RstinstrumentsIpi Utility1.05.0
RstinstrumentsRstar Rtu Host1.33.0
RstinstrumentsDt2011 Firmware1.19.4.0
RstinstrumentsDt2011b Firmware1.19.4.0
RstinstrumentsDt2040 Firmware1.19.4.0
RstinstrumentsDt2050 Firmware1.19.4.0
RstinstrumentsDt2050b Firmware1.19.4.0
RstinstrumentsDt2055b Firmware1.19.4.0
RstinstrumentsDt2306 Firmware1.19.4.0
RstinstrumentsDt2350 Firmware1.19.4.0

Showing 50 of 70 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-27438?
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.
How severe is CVE-2022-27438?
CVE-2022-27438 has a CVSS score of 8.1/10 (HIGH severity). The EPSS model estimates a 2.38% probability of exploitation in the next 30 days.
How do I fix CVE-2022-27438?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-27438?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST