CVE-2022-48222
- EPSS 0.06%
- Veröffentlicht 04.04.2023 16:15:07
- Zuletzt bearbeitet 18.02.2025 17:15:15
An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During SDK installation, certutil.exe is called by the Acuant installer to install certificates. This window is not hidden, and is running with elevated privileges. A standard user can...
CVE-2022-48223
- EPSS 0.04%
- Veröffentlicht 04.04.2023 16:15:07
- Zuletzt bearbeitet 18.02.2025 18:15:13
An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During SDK repair, certutil.exe is called by the Acuant installer to repair certificates. This call is vulnerable to DLL hijacking due to a race condition and insecure permissions on t...
CVE-2022-48224
- EPSS 0.06%
- Veröffentlicht 04.04.2023 16:15:07
- Zuletzt bearbeitet 18.02.2025 18:15:13
An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. It is installed with insecure permissions (full write access within Program Files). Standard users can replace files within this directory that get executed with elevated privileges, l...
CVE-2022-48221
- EPSS 0.15%
- Veröffentlicht 04.04.2023 15:15:08
- Zuletzt bearbeitet 18.02.2025 17:15:15
An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. Multiple MSI's get executed out of a standard-user writable directory. Through a race condition and OpLock manipulation, these files can be overwritten by a standard user. They then ge...
CVE-2022-48225
- EPSS 0.03%
- Veröffentlicht 04.04.2023 15:15:08
- Zuletzt bearbeitet 18.02.2025 18:15:13
An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. It is used to install drivers from several different vendors. The Gemalto Document Reader child installation process is vulnerable to DLL hijacking, because it attempts to execute (wit...
CVE-2022-48226
- EPSS 0.04%
- Veröffentlicht 04.04.2023 15:15:08
- Zuletzt bearbeitet 13.02.2025 22:15:08
An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During installation, an EXE gets executed out of C:\Windows\Temp. A standard user can create the path file ahead of time and obtain elevated code execution. Permissions need to be modi...