CVE-2022-27438

Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
caphyonadvanced_installer
𝑥
< 19.4
3cxcall_flow_designer
18.2.13
3cxcrm_template_generator
2.1.23
boomboomtv_streamer_portal
2.2.1
codesectordirect_folders
4.0
codesectorteracopy
3.8.5
emeditoremeditor
21.3.0
flamoryflamory
4.2.19.0
freesnippingtoolfree_snipping_tool
5.6.0.0
fxsoundfxsound
1.1.12.0
gainedgebetter_explorer
2020.3.15.1304
gamecastergamecaster
4.0.2109.2802
getmailbirdmailbird
2.9.50.0
guzogoguzogo
1.0.5.0
honeygainhoneygain
0.10.7.0
jkivi_package_manager
21.1.2754
jpsofttake_command
28.2.18
krylackarchive_password_recovery
3.70.69
krylackasterisks_password_decryptor
3.31.107
krylackburning_suite
1.20.05
krylackrar_password_recovery
3.70.69
krylackvolume_serial_number_editor
2.02.34
krylackzip_password_recovery
3.70.69
moonsoftwarepassword_agent
20.10.1
nefariusscptoolkit
1.6.238.16010
plagiarismcheckerxplagiarism_checker_x
8.0.6
prusa3dprusaslicer
2.4.2
realdefensemycleanid
4.1.4
realdefensemycleanpc
4.0.2
realdefensemypasslock
1.9.6
rovioangry_birds_space
1.4.1
roviobad_piggies
1.3.0
synapticsdisplaylink_usb_graphics
𝑥
< 10.3.6400.0
urban-vpnurban_vpn
2.2.5
vigemvigembus_driver
1.16.116
vpnhoodvpnhood
2.4.299
vrdesktopvirtual_desktop_streamer
1.20.16
xsplitxsplit_express_video_editor
3.0.2001.801
rstinstrumentsvw0420_firmware
1.33.0
rstinstrumentsinclinalysis_digital_inclinometer
2.48.9
rstinstrumentsipi_utility
1.05.0
rstinstrumentsrstar_rtu_host
1.33.0
rstinstrumentsdt2011_firmware
1.19.4.0
rstinstrumentsdt2011b_firmware
1.19.4.0
rstinstrumentsdt2040_firmware
1.19.4.0
rstinstrumentsdt2050_firmware
1.19.4.0
rstinstrumentsdt2050b_firmware
1.19.4.0
rstinstrumentsdt2055b_firmware
1.19.4.0
rstinstrumentsdt2306_firmware
1.19.4.0
rstinstrumentsdt2350_firmware
1.19.4.0
rstinstrumentsdt2485_firmware
1.19.4.0
rstinstrumentsdt4205_firmware
1.19.4.0
rstinstrumentsdtsaa_firmware
1.19.4.0
rstinstrumentsic6560_firmware
1.19.4.0
rstinstrumentsic6660_firmware
1.19.4.0
rstinstrumentsdtl201b\/2b_firmware
1.19.4.0
rstinstrumentsmtcm_firmware
1.19.4.0
rstinstrumentsgaa2820_firmware
1.19.4.0
rstinstrumentsrtu_firmware
1.19.4.0
rstinstrumentsmems_tilt_meter_firmware
1.20.1
rstinstrumentsportable_tilt_meter_firmware
1.20.1
rstinstrumentsvw2106_firmware
-
rstinstrumentsth2016_firmware
1.4.0.2
rstinstrumentsth2016b_firmware
1.4.0.2
rstinstrumentsma7_firmware
1.4.0.2
rstinstrumentsqb120_firmware
1.4.0.2
rstinstrumentssg350_firmware
1.4.0.2
rstinstrumentsir420_firmware
1.4.0.2
rstinstrumentslp100_firmware
1.4.0.2
rstinstrumentsc109_firmware
1.4.0.2
𝑥
= Vulnerable software versions