CVE-2022-27438

HIGH

Advanced Installer < 19.4 - Remote Code Execution via CustomDetection Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-27438. PoCs published by gar-re.

AI-analyzed exploit summary This PoC exploits CVE-2022-27438, a remote code execution vulnerability in Caphyon Ltd Advanced Installer 19.3. It leverages the 'CustomDetection' feature in the update mechanism to execute arbitrary commands by spoofing the update server and serving a malicious 'updates.ini' file.

Description

Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.

Exploits (1)

nomisec WORKING POC
by gar-re · poc
https://github.com/gar-re/cve-2022-27438

This PoC exploits CVE-2022-27438, a remote code execution vulnerability in Caphyon Ltd Advanced Installer 19.3. It leverages the 'CustomDetection' feature in the update mechanism to execute arbitrary commands by spoofing the update server and serving a malicious 'updates.ini' file.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Caphyon Ltd Advanced Installer 19.3
No auth needed
Prerequisites: DNS spoofing or hosts file modification · Self-signed certificate for the spoofed domain · Victim to trigger the update check
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Product x_refsource_misc
http://caphyon.com
Exploit, Third Party Advisory x_refsource_misc
https://gerr.re/posts/cve-2022-27438/
Product x_refsource_misc
http://advanced.com

Scores

CVSS v3 8.1
EPSS 0.0238
EPSS Percentile 81.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-494
Status published
Products (50)
3cx/call_flow_designer 18.2.13
3cx/crm_template_generator 2.1.23
boom/boomtv_streamer_portal 2.2.1
caphyon/advanced_installer < 19.4
codesector/direct_folders 4.0
codesector/teracopy 3.8.5
emeditor/emeditor 21.3.0
flamory/flamory 4.2.19.0
freesnippingtool/free_snipping_tool 5.6.0.0
fxsound/fxsound 1.1.12.0
... and 40 more
Published Jun 06, 2022
Tracked Since Feb 18, 2026