Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.
References
| Link | Resource |
|---|---|
| http://caphyon.com | Product |
| https://gerr.re/posts/cve-2022-27438/ | Exploit Third Party Advisory |
| http://advanced.com | Product |
| https://www.advancedinstaller.com/security-updates-auto-updater.html | Patch Vendor Advisory |
Configurations
Information
Published : 2022-06-06 23:15
Updated : 2022-06-21 19:39
NVD link : CVE-2022-27438
Mitre link : CVE-2022-27438
JSON object : View
Products Affected
caphyon
- advanced_installer
CWE
CWE-494
Download of Code Without Integrity Check
