Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
Link | Tags |
---|---|
http://advanced.com | product |
http://caphyon.com | product |
https://gerr.re/posts/cve-2022-27438/ | third party advisory exploit |
https://www.advancedinstaller.com/security-updates-auto-updater.html | patch vendor advisory |