8.1

CVE-2022-27438

Exploit

Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.

Data is provided by the National Vulnerability Database (NVD)
CaphyonAdvanced Installer Version < 19.4
3cxCall Flow Designer Version18.2.13
3cxCrm Template Generator Version2.1.23
BoomBoomtv Streamer Portal Version2.2.1
CodesectorDirect Folders Version4.0
CodesectorTeracopy Version3.8.5
EmeditorEmeditor Version21.3.0
FlamoryFlamory Version4.2.19.0
FxsoundFxsound Version1.1.12.0
GainedgeBetter Explorer Version2020.3.15.1304
GamecasterGamecaster Version4.0.2109.2802
GetmailbirdMailbird Version2.9.50.0
GuzogoGuzogo Version1.0.5.0
HoneygainHoneygain Version0.10.7.0 SwPlatformwindows
JkiVi Package Manager Version21.1.2754
JpsoftTake Command Version28.2.18
KrylackArchive Password Recovery Version3.70.69
KrylackBurning Suite Version1.20.05
KrylackRar Password Recovery Version3.70.69
KrylackZip Password Recovery Version3.70.69
MoonsoftwarePassword Agent Version20.10.1
NefariusScptoolkit Version1.6.238.16010
Prusa3dPrusaslicer Version2.4.2
RealdefenseMycleanid Version4.1.4
RealdefenseMycleanpc Version4.0.2
RealdefenseMypasslock Version1.9.6
RovioAngry Birds Space Version1.4.1
RovioBad Piggies Version1.3.0
SynapticsDisplaylink Usb Graphics SwPlatformwindows Version < 10.3.6400.0
Urban-vpnUrban Vpn Version2.2.5
VigemVigembus Driver Version1.16.116
VpnhoodVpnhood Version2.4.299 SwPlatformwindows
VrdesktopVirtual Desktop Streamer Version1.20.16
XsplitXsplit Express Video Editor Version3.0.2001.801
RstinstrumentsVw0420 Firmware Version1.33.0
   RstinstrumentsVw0420 Version-
RstinstrumentsIpi Utility Version1.05.0
RstinstrumentsRstar Rtu Host Version1.33.0
RstinstrumentsDt2011 Firmware Version1.19.4.0
   RstinstrumentsDt2011 Version-
RstinstrumentsDt2011b Firmware Version1.19.4.0
   RstinstrumentsDt2011b Version-
RstinstrumentsDt2040 Firmware Version1.19.4.0
   RstinstrumentsDt2040 Version-
RstinstrumentsDt2050 Firmware Version1.19.4.0
   RstinstrumentsDt2050 Version-
RstinstrumentsDt2050b Firmware Version1.19.4.0
   RstinstrumentsDt2050b Version-
RstinstrumentsDt2055b Firmware Version1.19.4.0
   RstinstrumentsDt2055b Version-
RstinstrumentsDt2306 Firmware Version1.19.4.0
   RstinstrumentsDt2306 Version-
RstinstrumentsDt2350 Firmware Version1.19.4.0
   RstinstrumentsDt2350 Version-
RstinstrumentsDt2485 Firmware Version1.19.4.0
   RstinstrumentsDt2485 Version-
RstinstrumentsDt4205 Firmware Version1.19.4.0
   RstinstrumentsDt4205 Version-
RstinstrumentsDtsaa Firmware Version1.19.4.0
   RstinstrumentsDtsaa Version-
RstinstrumentsIc6560 Firmware Version1.19.4.0
   RstinstrumentsIc6560 Version-
RstinstrumentsIc6660 Firmware Version1.19.4.0
   RstinstrumentsIc6660 Version-
RstinstrumentsDtl201b/2b Firmware Version1.19.4.0
   RstinstrumentsDtl201b/2b Version-
RstinstrumentsMtcm Firmware Version1.19.4.0
   RstinstrumentsMtcm Version-
RstinstrumentsGaa2820 Firmware Version1.19.4.0
   RstinstrumentsGaa2820 Version-
RstinstrumentsRtu Firmware Version1.19.4.0
   RstinstrumentsRtu Version-
RstinstrumentsVw2106 Firmware Version-
   RstinstrumentsVw2106 Version-
RstinstrumentsTh2016 Firmware Version1.4.0.2
   RstinstrumentsTh2016 Version-
RstinstrumentsTh2016b Firmware Version1.4.0.2
   RstinstrumentsTh2016b Version-
RstinstrumentsMa7 Firmware Version1.4.0.2
   RstinstrumentsMa7 Version-
RstinstrumentsQb120 Firmware Version1.4.0.2
   RstinstrumentsQb120 Version-
RstinstrumentsSg350 Firmware Version1.4.0.2
   RstinstrumentsSg350 Version-
RstinstrumentsIr420 Firmware Version1.4.0.2
   RstinstrumentsIr420 Version-
RstinstrumentsLp100 Firmware Version1.4.0.2
   RstinstrumentsLp100 Version-
RstinstrumentsC109 Firmware Version1.4.0.2
   RstinstrumentsC109 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 12.34% 0.936
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
CWE-494 Download of Code Without Integrity Check

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.