PT-2023-15623 · Acuant · Acuant Acufill Sdk
Published
2023-04-04
·
Updated
2025-02-13
·
CVE-2022-48226
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Acuant AcuFill SDK versions prior to 10.22.02.03
Description
An issue was discovered in the Acuant AcuFill SDK. During installation, an executable file gets executed out of the C:WindowsTemp directory. A standard user can create the path file ahead of time and obtain elevated code execution. Permissions need to be modified to prevent manipulation.
Recommendations
For versions prior to 10.22.02.03, modify the permissions to prevent manipulation and restrict access to the C:WindowsTemp directory to prevent a standard user from creating the path file ahead of time. Update to version 10.22.02.03 or later to resolve the issue.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acuant Acufill Sdk