CVE-2022-27438

HIGH

Caphyon Advanced Installer < 19.4 - Download Without Integrity Check

Title source: rule
STIX 2.1

Description

Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.

Exploits (1)

nomisec WORKING POC
by gar-re · poc
https://github.com/gar-re/cve-2022-27438

Scores

CVSS v3 8.1
EPSS 0.1227
EPSS Percentile 93.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-494
Status published
Products (50)
3cx/call_flow_designer 18.2.13
3cx/crm_template_generator 2.1.23
boom/boomtv_streamer_portal 2.2.1
caphyon/advanced_installer < 19.4
codesector/direct_folders 4.0
codesector/teracopy 3.8.5
emeditor/emeditor 21.3.0
flamory/flamory 4.2.19.0
freesnippingtool/free_snipping_tool 5.6.0.0
fxsound/fxsound 1.1.12.0
... and 40 more
Published Jun 06, 2022
Tracked Since Feb 18, 2026