An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During SDK repair, certutil.exe is called by the Acuant installer to repair certificates. This call is vulnerable to DLL hijacking due to a race condition and insecure permissions on the executing directory.
References
Link | Resource |
---|---|
https://acuant.com | Not Applicable |
https://hackandpwn.com/disclosures/CVE-2022-48223.pdf | Third Party Advisory |
https://acuant.com | Not Applicable |
https://hackandpwn.com/disclosures/CVE-2022-48223.pdf | Third Party Advisory |
Configurations
History
21 Nov 2024, 07:32
Type | Values Removed | Values Added |
---|---|---|
References | () https://acuant.com - Not Applicable | |
References | () https://hackandpwn.com/disclosures/CVE-2022-48223.pdf - Third Party Advisory |
Information
Published : 2023-04-04 16:15
Updated : 2024-11-21 07:32
NVD link : CVE-2022-48223
Mitre link : CVE-2022-48223
CVE.ORG link : CVE-2022-48223
JSON object : View
Products Affected
gbgplc
- acuant_acufill_sdk
CWE
CWE-427
Uncontrolled Search Path Element