CVE-2022-48223
Summary
| CVE | CVE-2022-48223 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-04 16:15:00 UTC |
| Updated | 2023-04-11 14:53:00 UTC |
| Description | An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During SDK repair, certutil.exe is called by the Acuant installer to repair certificates. This call is vulnerable to DLL hijacking due to a race condition and insecure permissions on the executing directory. |
Risk And Classification
Problem Types: CWE-427
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gbgplc | Acuant Acufill Sdk | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Document Authentication Software - Identity Verification and KYC Solutions | MISC | acuant.com | |
| hackandpwn.com/disclosures/CVE-2022-48223.pdf | MISC | hackandpwn.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.