Caphyon · Caphyon Advanced Installer · CVE-2022-4956
**Name of the Vulnerable Software and Affected Versions**
Caphyon Advanced Installer version 19.7
**Description**
A critical vulnerability has been found in the WinSxS DLL Handler component of Caphyon Advanced Installer. The manipulation leads to an uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to the public.
**Recommendations**
For Caphyon Advanced Installer version 19.7, upgrade to version 19.7.1 to address this issue. It is recommended to upgrade the affected component. As a temporary workaround, consider restricting access to the WinSxS DLL Handler until the update is applied.