CVE-2022-27438

Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:caphyon:advanced_installer:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:3cx:call_flow_designer:18.2.13:*:*:*:*:*:*:*
cpe:2.3:a:3cx:crm_template_generator:2.1.23:*:*:*:*:*:*:*
cpe:2.3:a:boom:boomtv_streamer_portal:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:codesector:direct_folders:4.0:*:*:*:*:*:*:*
cpe:2.3:a:codesector:teracopy:3.8.5:*:*:*:*:*:*:*
cpe:2.3:a:emeditor:emeditor:21.3.0:*:*:*:*:*:*:*
cpe:2.3:a:flamory:flamory:4.2.19.0:*:*:*:*:*:*:*
cpe:2.3:a:freesnippingtool:free_snipping_tool:5.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fxsound:fxsound:1.1.12.0:*:*:*:*:*:*:*
cpe:2.3:a:gainedge:better_explorer:2020.3.15.1304:*:*:*:*:*:*:*
cpe:2.3:a:gamecaster:gamecaster:4.0.2109.2802:*:*:*:*:*:*:*
cpe:2.3:a:getmailbird:mailbird:2.9.50.0:*:*:*:*:*:*:*
cpe:2.3:a:guzogo:guzogo:1.0.5.0:*:*:*:*:*:*:*
cpe:2.3:a:honeygain:honeygain:0.10.7.0:*:*:*:*:windows:*:*
cpe:2.3:a:jki:vi_package_manager:21.1.2754:*:*:*:*:*:*:*
cpe:2.3:a:jpsoft:take_command:28.2.18:*:*:*:*:*:*:*
cpe:2.3:a:krylack:archive_password_recovery:3.70.69:*:*:*:*:*:*:*
cpe:2.3:a:krylack:asterisks_password_decryptor:3.31.107:*:*:*:*:*:*:*
cpe:2.3:a:krylack:burning_suite:1.20.05:*:*:*:*:*:*:*
cpe:2.3:a:krylack:rar_password_recovery:3.70.69:*:*:*:*:*:*:*
cpe:2.3:a:krylack:volume_serial_number_editor:2.02.34:*:*:*:*:*:*:*
cpe:2.3:a:krylack:zip_password_recovery:3.70.69:*:*:*:*:*:*:*
cpe:2.3:a:moonsoftware:password_agent:20.10.1:*:*:*:*:*:*:*
cpe:2.3:a:nefarius:scptoolkit:1.6.238.16010:*:*:*:*:*:*:*
cpe:2.3:a:plagiarismcheckerx:plagiarism_checker_x:8.0.6:*:*:*:*:*:*:*
cpe:2.3:a:prusa3d:prusaslicer:2.4.2:*:*:*:*:*:*:*
cpe:2.3:a:realdefense:mycleanid:4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:realdefense:mycleanpc:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:realdefense:mypasslock:1.9.6:*:*:*:*:*:*:*
cpe:2.3:a:rovio:angry_birds_space:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:rovio:bad_piggies:1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:synaptics:displaylink_usb_graphics:*:*:*:*:*:windows:*:*
cpe:2.3:a:urban-vpn:urban_vpn:2.2.5:*:*:*:*:*:*:*
cpe:2.3:a:vigem:vigembus_driver:1.16.116:*:*:*:*:*:*:*
cpe:2.3:a:vpnhood:vpnhood:2.4.299:*:*:*:*:windows:*:*
cpe:2.3:a:vrdesktop:virtual_desktop_streamer:1.20.16:*:*:*:*:*:*:*
cpe:2.3:a:xsplit:xsplit_express_video_editor:3.0.2001.801:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:rstinstruments:vw0420_firmware:1.33.0:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:vw0420:-:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:rstinstruments:inclinalysis_digital_inclinometer:2.48.9:*:*:*:*:*:*:*
cpe:2.3:a:rstinstruments:ipi_utility:1.05.0:*:*:*:*:*:*:*
cpe:2.3:o:rstinstruments:rstar_rtu_host:1.33.0:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:rstinstruments:dt2011_firmware:1.19.4.0:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:dt2011:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:rstinstruments:dt2011b_firmware:1.19.4.0:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:dt2011b:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:rstinstruments:dt2040_firmware:1.19.4.0:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:dt2040:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:rstinstruments:dt2050_firmware:1.19.4.0:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:dt2050:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:rstinstruments:dt2050b_firmware:1.19.4.0:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:dt2050b:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:rstinstruments:dt2055b_firmware:1.19.4.0:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:dt2055b:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:rstinstruments:dt2306_firmware:1.19.4.0:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:dt2306:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:rstinstruments:dt2350_firmware:1.19.4.0:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:dt2350:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:rstinstruments:dt2485_firmware:1.19.4.0:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:dt2485:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:rstinstruments:dt4205_firmware:1.19.4.0:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:dt4205:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:rstinstruments:dtsaa_firmware:1.19.4.0:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:dtsaa:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:rstinstruments:ic6560_firmware:1.19.4.0:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:ic6560:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:rstinstruments:ic6660_firmware:1.19.4.0:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:ic6660:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:rstinstruments:dtl201b\/2b_firmware:1.19.4.0:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:dtl201b\/2b:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:rstinstruments:mtcm_firmware:1.19.4.0:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:mtcm:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:rstinstruments:gaa2820_firmware:1.19.4.0:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:gaa2820:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:rstinstruments:rtu_firmware:1.19.4.0:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:rtu:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:rstinstruments:mems_tilt_meter_firmware:1.20.1:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:mems_tilt_meter:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:rstinstruments:portable_tilt_meter_firmware:1.20.1:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:portable_tilt_meter:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:rstinstruments:vw2106_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:vw2106:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:rstinstruments:th2016_firmware:1.4.0.2:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:th2016:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:rstinstruments:th2016b_firmware:1.4.0.2:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:th2016b:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:rstinstruments:ma7_firmware:1.4.0.2:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:ma7:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:rstinstruments:qb120_firmware:1.4.0.2:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:qb120:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:rstinstruments:sg350_firmware:1.4.0.2:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:sg350:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:rstinstruments:ir420_firmware:1.4.0.2:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:ir420:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:rstinstruments:lp100_firmware:1.4.0.2:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:lp100:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:rstinstruments:c109_firmware:1.4.0.2:*:*:*:*:*:*:*
cpe:2.3:h:rstinstruments:c109:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-06-06 23:15

Updated : 2024-02-28 19:09


NVD link : CVE-2022-27438

Mitre link : CVE-2022-27438

CVE.ORG link : CVE-2022-27438


JSON object : View

Products Affected

rstinstruments

  • th2016b_firmware
  • dt2011b_firmware
  • ic6560_firmware
  • dt2350_firmware
  • sg350
  • dtl201b\/2b_firmware
  • ipi_utility
  • portable_tilt_meter
  • ic6660_firmware
  • qb120
  • sg350_firmware
  • dtsaa
  • vw2106
  • lp100_firmware
  • dt2485
  • portable_tilt_meter_firmware
  • ic6660
  • dt2040
  • mems_tilt_meter_firmware
  • ic6560
  • inclinalysis_digital_inclinometer
  • mtcm_firmware
  • th2016b
  • ir420_firmware
  • mtcm
  • dt4205_firmware
  • gaa2820_firmware
  • ma7_firmware
  • vw0420_firmware
  • dtsaa_firmware
  • dt2485_firmware
  • dt2306
  • dt2011b
  • dt2050
  • rtu_firmware
  • c109
  • lp100
  • dt2011_firmware
  • th2016_firmware
  • dt2050b_firmware
  • rtu
  • ma7
  • vw2106_firmware
  • gaa2820
  • dt2050_firmware
  • ir420
  • dt2055b_firmware
  • dt2050b
  • dt2306_firmware
  • th2016
  • dt2011
  • qb120_firmware
  • mems_tilt_meter
  • dt2040_firmware
  • rstar_rtu_host
  • dt4205
  • dt2350
  • vw0420
  • c109_firmware
  • dt2055b
  • dtl201b\/2b

plagiarismcheckerx

  • plagiarism_checker_x

rovio

  • bad_piggies
  • angry_birds_space

guzogo

  • guzogo

krylack

  • volume_serial_number_editor
  • asterisks_password_decryptor
  • zip_password_recovery
  • burning_suite
  • archive_password_recovery
  • rar_password_recovery

caphyon

  • advanced_installer

freesnippingtool

  • free_snipping_tool

codesector

  • teracopy
  • direct_folders

jpsoft

  • take_command

synaptics

  • displaylink_usb_graphics

nefarius

  • scptoolkit

getmailbird

  • mailbird

honeygain

  • honeygain

3cx

  • crm_template_generator
  • call_flow_designer

emeditor

  • emeditor

moonsoftware

  • password_agent

gainedge

  • better_explorer

flamory

  • flamory

jki

  • vi_package_manager

vrdesktop

  • virtual_desktop_streamer

gamecaster

  • gamecaster

realdefense

  • mycleanid
  • mypasslock
  • mycleanpc

fxsound

  • fxsound

urban-vpn

  • urban_vpn

vpnhood

  • vpnhood

prusa3d

  • prusaslicer

xsplit

  • xsplit_express_video_editor

boom

  • boomtv_streamer_portal

vigem

  • vigembus_driver
CWE
CWE-494

Download of Code Without Integrity Check