An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During SDK repair, certutil.exe is called by the Acuant installer to repair certificates. This call is vulnerable to DLL hijacking due to a race condition and insecure permissions on the executing directory.
References
Link | Resource |
---|---|
https://acuant.com | Not Applicable |
https://acuant.com | Not Applicable |
https://hackandpwn.com/disclosures/CVE-2022-48223.pdf | Third Party Advisory |
https://hackandpwn.com/disclosures/CVE-2022-48223.pdf | Third Party Advisory |
Configurations
History
14 Feb 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://acuant.com - Not Applicable | |
References | () https://hackandpwn.com/disclosures/CVE-2022-48223.pdf - Third Party Advisory |
11 Apr 2023, 14:53
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:gbgplc:acuant_acufill_sdk:*:*:*:*:*:*:*:* | |
CWE | CWE-427 | |
References | (MISC) https://hackandpwn.com/disclosures/CVE-2022-48223.pdf - Third Party Advisory | |
References | (MISC) https://acuant.com - Not Applicable | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.7 |
First Time |
Gbgplc
Gbgplc acuant Acufill Sdk |
04 Apr 2023, 17:40
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-04 16:15
Updated : 2025-02-18 18:15
NVD link : CVE-2022-48223
Mitre link : CVE-2022-48223
JSON object : View
Products Affected
gbgplc
- acuant_acufill_sdk
CWE
CWE-427
Uncontrolled Search Path Element