CVE-2022-48223
Last modified
CVE-2022-48223 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During SDK repair, certutil.exe is called by the Acuant installer to repair certificates. EPSS estimates a 0.11% chance of exploitation in the next 30 days.
Description
An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During SDK repair, certutil.exe is called by the Acuant installer to repair certificates. This call is vulnerable to DLL hijacking due to a race condition and insecure permissions on the executing directory.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gbgplc | Acuant Acufill Sdk | < 10.22.02.03 |
References
- https://acuant.comNot Applicable
- https://hackandpwn.com/disclosures/CVE-2022-48223.pdfThird Party Advisory
- https://acuant.comNot Applicable
- https://hackandpwn.com/disclosures/CVE-2022-48223.pdfThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-48223?
How severe is CVE-2022-48223?
How do I fix CVE-2022-48223?
Are you affected by CVE-2022-48223?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
