HIGH · 8.1

CVE-2022-27438

Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDe...

Vulnerability Description

Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.

CVSS Score

8.1

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CaphyonAdvanced Installer< 19.4
3CxCall Flow Designer18.2.13
3CxCrm Template Generator2.1.23
BoomBoomtv Streamer Portal2.2.1
CodesectorDirect Folders4.0
CodesectorTeracopy3.8.5
EmeditorEmeditor21.3.0
FlamoryFlamory4.2.19.0
FreesnippingtoolFree Snipping Tool5.6.0.0
FxsoundFxsound1.1.12.0
GainedgeBetter Explorer2020.3.15.1304
GamecasterGamecaster4.0.2109.2802
GetmailbirdMailbird2.9.50.0
GuzogoGuzogo1.0.5.0
HoneygainHoneygain0.10.7.0
JkiVi Package Manager21.1.2754
JpsoftTake Command28.2.18
KrylackArchive Password Recovery3.70.69
KrylackAsterisks Password Decryptor3.31.107
KrylackBurning Suite1.20.05

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-27438?

CVE-2022-27438 is a vulnerability with a CVSS score of 8.1 (HIGH). Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDe...

How severe is CVE-2022-27438?

CVE-2022-27438 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-27438?

Check the references section above for vendor advisories and patch information. Affected products include: Caphyon Advanced Installer, 3Cx Call Flow Designer, 3Cx Crm Template Generator, Boom Boomtv Streamer Portal, Codesector Direct Folders.