CVE-2022-48225

An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. It is used to install drivers from several different vendors. The Gemalto Document Reader child installation process is vulnerable to DLL hijacking, because it attempts to execute (with elevated privileges) multiple non-existent DLLs out of a non-existent standard-user writable location.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:gbgplc:acuant_acufill_sdk:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:32

Type Values Removed Values Added
References () https://acuant.com - Not Applicable () https://acuant.com - Not Applicable
References () https://hackandpwn.com/disclosures/CVE-2022-48225.pdf - Third Party Advisory () https://hackandpwn.com/disclosures/CVE-2022-48225.pdf - Third Party Advisory

11 Apr 2023, 15:37

Type Values Removed Values Added
CWE CWE-427
References (MISC) https://hackandpwn.com/disclosures/CVE-2022-48225.pdf - (MISC) https://hackandpwn.com/disclosures/CVE-2022-48225.pdf - Third Party Advisory
References (MISC) https://acuant.com - (MISC) https://acuant.com - Not Applicable
First Time Gbgplc acuant Acufill Sdk
Gbgplc
CPE cpe:2.3:a:gbgplc:acuant_acufill_sdk:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3

04 Apr 2023, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-04 15:15

Updated : 2025-02-18 18:15


NVD link : CVE-2022-48225

Mitre link : CVE-2022-48225

CVE.ORG link : CVE-2022-48225


JSON object : View

Products Affected

gbgplc

  • acuant_acufill_sdk
CWE
CWE-427

Uncontrolled Search Path Element