An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During SDK repair, certutil.exe is called by the Acuant installer to repair certificates. This call is vulnerable to DLL hijacking due to a race condition and insecure permissions on the executing directory.
References
Link | Resource |
---|---|
https://acuant.com | Not Applicable |
https://hackandpwn.com/disclosures/CVE-2022-48223.pdf | Third Party Advisory |
https://acuant.com | Not Applicable |
https://hackandpwn.com/disclosures/CVE-2022-48223.pdf | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-04-04 16:15
Updated : 2025-02-18 18:15
NVD link : CVE-2022-48223
Mitre link : CVE-2022-48223
CVE.ORG link : CVE-2022-48223
JSON object : View
Products Affected
gbgplc
- acuant_acufill_sdk
CWE
CWE-427
Uncontrolled Search Path Element