CVE-2022-48224
Summary
| CVE | CVE-2022-48224 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-04 16:15:00 UTC |
| Updated | 2023-04-11 14:53:00 UTC |
| Description | An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. It is installed with insecure permissions (full write access within Program Files). Standard users can replace files within this directory that get executed with elevated privileges, leading to a complete arbitrary code execution (elevation of privileges). |
Risk And Classification
Problem Types: CWE-427
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gbgplc | Acuant Acufill Sdk | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Document Authentication Software - Identity Verification and KYC Solutions | MISC | acuant.com | |
| hackandpwn.com/disclosures/CVE-2022-48224.pdf | MISC | hackandpwn.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.