Unknown
CVE-2022-27438
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2022-27438
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- advanced installer,
- angry birds space 1.4.1,
- archive password recovery 3.70.69,
- asterisks password decryptor 3.31.107,
- bad piggies 1.3.0,
- better explorer 2020.3.15.1304,
- boomtv streamer portal 2.2.1,
- burning suite 1.20.05,
- c109 firmware 1.4.0.2,
- call flow designer 18.2.13,
- crm template generator 2.1.23,
- direct folders 4.0,
- displaylink usb graphics,
- dt2011 firmware 1.19.4.0,
- dt2011b firmware 1.19.4.0,
- dt2040 firmware 1.19.4.0,
- dt2050 firmware 1.19.4.0,
- dt2050b firmware 1.19.4.0,
- dt2055b firmware 1.19.4.0,
- dt2306 firmware 1.19.4.0,
- dt2350 firmware 1.19.4.0,
- dt2485 firmware 1.19.4.0,
- dt4205 firmware 1.19.4.0,
- dtl201b/2b firmware 1.19.4.0,
- dtsaa firmware 1.19.4.0,
- emeditor 21.3.0,
- flamory 4.2.19.0,
- free snipping tool 5.6.0.0,
- fxsound 1.1.12.0,
- gaa2820 firmware 1.19.4.0,
- gamecaster 4.0.2109.2802,
- guzogo 1.0.5.0,
- honeygain 0.10.7.0,
- ic6560 firmware 1.19.4.0,
- ic6660 firmware 1.19.4.0,
- inclinalysis digital inclinometer 2.48.9,
- ipi utility 1.05.0,
- ir420 firmware 1.4.0.2,
- lp100 firmware 1.4.0.2,
- ma7 firmware 1.4.0.2,
- mailbird 2.9.50.0,
- mems tilt meter firmware 1.20.1,
- mtcm firmware 1.19.4.0,
- mycleanid 4.1.4,
- mycleanpc 4.0.2,
- mypasslock 1.9.6,
- password agent 20.10.1,
- plagiarism checker x 8.0.6,
- portable tilt meter firmware 1.20.1,
- prusaslicer 2.4.2,
- qb120 firmware 1.4.0.2,
- rar password recovery 3.70.69,
- rstar rtu host 1.33.0,
- rtu firmware 1.19.4.0,
- scptoolkit 1.6.238.16010,
- sg350 firmware 1.4.0.2,
- take command 28.2.18,
- teracopy 3.8.5,
- th2016 firmware 1.4.0.2,
- th2016b firmware 1.4.0.2,
- urban vpn 2.2.5,
- vi package manager 21.1.2754,
- vigembus driver 1.16.116,
- virtual desktop streamer 1.20.16,
- volume serial number editor 2.02.34,
- vpnhood 2.4.299,
- vw0420 firmware 1.33.0,
- vw2106 firmware -,
- xsplit express video editor 3.0.2001.801,
- zip password recovery 3.70.69
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: