ZeroHour

CVE-2022-48224

CVSS 3.1
7.3 high
EPSS
<1%p12
Published
()
Modified
Description

An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. It is installed with insecure permissions (full write access within Program Files). Standard users can replace files within this directory that get executed with elevated privileges, leading to a complete arbitrary code execution (elevation of privileges).

Vendors
gbgplc
Products
acuant acufill sdk
Weakness
CWE-427
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.