CVE-2022-27438
Summary
| CVE | CVE-2022-27438 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-06 23:15:00 UTC |
| Updated | 2023-04-28 19:03:00 UTC |
| Description | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check. |
Risk And Classification
Problem Types: CWE-494
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | 3cx | Call Flow Designer | 18.2.13 | All | All | All |
| Application | 3cx | Crm Template Generator | 2.1.23 | All | All | All |
| Application | Boom | Boomtv Streamer Portal | 2.2.1 | All | All | All |
| Application | Caphyon | Advanced Installer | All | All | All | All |
| Application | Codesector | Direct Folders | 4.0 | All | All | All |
| Application | Codesector | Teracopy | 3.8.5 | All | All | All |
| Application | Emeditor | Emeditor | 21.3.0 | All | All | All |
| Application | Flamory | Flamory | 4.2.19.0 | All | All | All |
| Application | Freesnippingtool | Free Snipping Tool | 5.6.0.0 | All | All | All |
| Application | Fxsound | Fxsound | 1.1.12.0 | All | All | All |
| Application | Gainedge | Better Explorer | 2020.3.15.1304 | All | All | All |
| Application | Gamecaster | Gamecaster | 4.0.2109.2802 | All | All | All |
| Application | Getmailbird | Mailbird | 2.9.50.0 | All | All | All |
| Application | Guzogo | Guzogo | 1.0.5.0 | All | All | All |
| Application | Honeygain | Honeygain | 0.10.7.0 | All | All | All |
| Application | Jki | Vi Package Manager | 21.1.2754 | All | All | All |
| Application | Jpsoft | Take Command | 28.2.18 | All | All | All |
| Application | Krylack | Archive Password Recovery | 3.70.69 | All | All | All |
| Application | Krylack | Asterisks Password Decryptor | 3.31.107 | All | All | All |
| Application | Krylack | Burning Suite | 1.20.05 | All | All | All |
| Application | Krylack | Rar Password Recovery | 3.70.69 | All | All | All |
| Application | Krylack | Volume Serial Number Editor | 2.02.34 | All | All | All |
| Application | Krylack | Zip Password Recovery | 3.70.69 | All | All | All |
| Application | Moonsoftware | Password Agent | 20.10.1 | All | All | All |
| Application | Nefarius | Scptoolkit | 1.6.238.16010 | All | All | All |
| Application | Plagiarismcheckerx | Plagiarism Checker X | 8.0.6 | All | All | All |
| Application | Prusa3d | Prusaslicer | 2.4.2 | All | All | All |
| Application | Realdefense | Mycleanid | 4.1.4 | All | All | All |
| Application | Realdefense | Mycleanpc | 4.0.2 | All | All | All |
| Application | Realdefense | Mypasslock | 1.9.6 | All | All | All |
| Application | Rovio | Angry Birds Space | 1.4.1 | All | All | All |
| Application | Rovio | Bad Piggies | 1.3.0 | All | All | All |
| Hardware | Rstinstruments | C109 | - | All | All | All |
| Operating System | Rstinstruments | C109 Firmware | 1.4.0.2 | All | All | All |
| Hardware | Rstinstruments | Dt2011 | - | All | All | All |
| Hardware | Rstinstruments | Dt2011b | - | All | All | All |
| Operating System | Rstinstruments | Dt2011b Firmware | 1.19.4.0 | All | All | All |
| Operating System | Rstinstruments | Dt2011 Firmware | 1.19.4.0 | All | All | All |
| Hardware | Rstinstruments | Dt2040 | - | All | All | All |
| Operating System | Rstinstruments | Dt2040 Firmware | 1.19.4.0 | All | All | All |
| Hardware | Rstinstruments | Dt2050 | - | All | All | All |
| Hardware | Rstinstruments | Dt2050b | - | All | All | All |
| Operating System | Rstinstruments | Dt2050b Firmware | 1.19.4.0 | All | All | All |
| Operating System | Rstinstruments | Dt2050 Firmware | 1.19.4.0 | All | All | All |
| Hardware | Rstinstruments | Dt2055b | - | All | All | All |
| Operating System | Rstinstruments | Dt2055b Firmware | 1.19.4.0 | All | All | All |
| Hardware | Rstinstruments | Dt2306 | - | All | All | All |
| Operating System | Rstinstruments | Dt2306 Firmware | 1.19.4.0 | All | All | All |
| Hardware | Rstinstruments | Dt2350 | - | All | All | All |
| Operating System | Rstinstruments | Dt2350 Firmware | 1.19.4.0 | All | All | All |
| Hardware | Rstinstruments | Dt2485 | - | All | All | All |
| Operating System | Rstinstruments | Dt2485 Firmware | 1.19.4.0 | All | All | All |
| Hardware | Rstinstruments | Dt4205 | - | All | All | All |
| Operating System | Rstinstruments | Dt4205 Firmware | 1.19.4.0 | All | All | All |
| Hardware | Rstinstruments | Dtl201b/2b | - | All | All | All |
| Operating System | Rstinstruments | Dtl201b/2b Firmware | 1.19.4.0 | All | All | All |
| Hardware | Rstinstruments | Dtsaa | - | All | All | All |
| Operating System | Rstinstruments | Dtsaa Firmware | 1.19.4.0 | All | All | All |
| Hardware | Rstinstruments | Gaa2820 | - | All | All | All |
| Operating System | Rstinstruments | Gaa2820 Firmware | 1.19.4.0 | All | All | All |
| Hardware | Rstinstruments | Ic6560 | - | All | All | All |
| Operating System | Rstinstruments | Ic6560 Firmware | 1.19.4.0 | All | All | All |
| Hardware | Rstinstruments | Ic6660 | - | All | All | All |
| Operating System | Rstinstruments | Ic6660 Firmware | 1.19.4.0 | All | All | All |
| Application | Rstinstruments | Inclinalysis Digital Inclinometer | 2.48.9 | All | All | All |
| Application | Rstinstruments | Ipi Utility | 1.05.0 | All | All | All |
| Hardware | Rstinstruments | Ir420 | - | All | All | All |
| Operating System | Rstinstruments | Ir420 Firmware | 1.4.0.2 | All | All | All |
| Hardware | Rstinstruments | Lp100 | - | All | All | All |
| Operating System | Rstinstruments | Lp100 Firmware | 1.4.0.2 | All | All | All |
| Hardware | Rstinstruments | Ma7 | - | All | All | All |
| Operating System | Rstinstruments | Ma7 Firmware | 1.4.0.2 | All | All | All |
| Hardware | Rstinstruments | Mems Tilt Meter | - | All | All | All |
| Operating System | Rstinstruments | Mems Tilt Meter Firmware | 1.20.1 | All | All | All |
| Hardware | Rstinstruments | Mtcm | - | All | All | All |
| Operating System | Rstinstruments | Mtcm Firmware | 1.19.4.0 | All | All | All |
| Hardware | Rstinstruments | Portable Tilt Meter | - | All | All | All |
| Operating System | Rstinstruments | Portable Tilt Meter Firmware | 1.20.1 | All | All | All |
| Hardware | Rstinstruments | Qb120 | - | All | All | All |
| Operating System | Rstinstruments | Qb120 Firmware | 1.4.0.2 | All | All | All |
| Operating System | Rstinstruments | Rstar Rtu Host | 1.33.0 | All | All | All |
| Hardware | Rstinstruments | Rtu | - | All | All | All |
| Operating System | Rstinstruments | Rtu Firmware | 1.19.4.0 | All | All | All |
| Hardware | Rstinstruments | Sg350 | - | All | All | All |
| Operating System | Rstinstruments | Sg350 Firmware | 1.4.0.2 | All | All | All |
| Hardware | Rstinstruments | Th2016 | - | All | All | All |
| Hardware | Rstinstruments | Th2016b | - | All | All | All |
| Operating System | Rstinstruments | Th2016b Firmware | 1.4.0.2 | All | All | All |
| Operating System | Rstinstruments | Th2016 Firmware | 1.4.0.2 | All | All | All |
| Hardware | Rstinstruments | Vw0420 | - | All | All | All |
| Operating System | Rstinstruments | Vw0420 Firmware | 1.33.0 | All | All | All |
| Hardware | Rstinstruments | Vw2106 | - | All | All | All |
| Operating System | Rstinstruments | Vw2106 Firmware | - | All | All | All |
| Application | Synaptics | Displaylink Usb Graphics | All | All | All | All |
| Application | Urban-vpn | Urban Vpn | 2.2.5 | All | All | All |
| Application | Vigem | Vigembus Driver | 1.16.116 | All | All | All |
| Application | Vpnhood | Vpnhood | 2.4.299 | All | All | All |
| Application | Vrdesktop | Virtual Desktop Streamer | 1.20.16 | All | All | All |
| Application | Xsplit | Xsplit Express Video Editor | 3.0.2001.801 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Caphyon Ltd | MISC | caphyon.com | |
| Important Security Updates for the Advanced Installer Auto Updater | MISC | www.advancedinstaller.com | |
| Advanced Interconnections | Interconnect Solutions | MISC | advanced.com | |
| CVE-2022-27438 | Gerr.re | MISC | gerr.re | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.