PT-2023-15623 · Acuant · Acuant Acufill Sdk

Published

2023-04-04

·

Updated

2025-02-13

·

CVE-2022-48226

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Acuant AcuFill SDK versions prior to 10.22.02.03
Description An issue was discovered in the Acuant AcuFill SDK. During installation, an executable file gets executed out of the C:WindowsTemp directory. A standard user can create the path file ahead of time and obtain elevated code execution. Permissions need to be modified to prevent manipulation.
Recommendations For versions prior to 10.22.02.03, modify the permissions to prevent manipulation and restrict access to the C:WindowsTemp directory to prevent a standard user from creating the path file ahead of time. Update to version 10.22.02.03 or later to resolve the issue.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2022-48226

Affected Products

Acuant Acufill Sdk