CVE-2022-27438 - CVE House
Back to Database
Status published High CVE-2022-27438

Caphyon Ltd Advanced Installer 19.3 and earlier and many products...

Vulnerability Description

Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-27438

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

advanced installer, call flow designer, crm template generator, boomtv streamer portal, direct folders, teracopy, emeditor, flamory, free snipping tool, fxsound, better explorer, gamecaster, mailbird, guzogo, honeygain, vi package manager, take command, archive password recovery, asterisks password decryptor, burning suite, rar password recovery, volume serial number editor, zip password recovery, password agent, scptoolkit, plagiarism checker x, prusaslicer, mycleanid, mycleanpc, mypasslock, angry birds space, bad piggies, displaylink usb graphics, urban vpn, vigembus driver, vpnhood, virtual desktop streamer, xsplit express video editor, vw0420 firmware, inclinalysis digital inclinometer, ipi utility, rstar rtu host, dt2011 firmware, dt2011b firmware, dt2040 firmware, dt2050 firmware, dt2050b firmware, dt2055b firmware, dt2306 firmware, dt2350 firmware, dt2485 firmware, dt4205 firmware, dtsaa firmware, ic6560 firmware, ic6660 firmware, dtl201b\/2b firmware, mtcm firmware, gaa2820 firmware, rtu firmware, mems tilt meter firmware, portable tilt meter firmware, vw2106 firmware, th2016 firmware, th2016b firmware, ma7 firmware, qb120 firmware, sg350 firmware, ir420 firmware, lp100 firmware, c109 firmware
Vulnerable Versions:
0, 18.2.13, 2.1.23, 2.2.1, 4.0, 3.8.5, 21.3.0, 4.2.19.0, 5.6.0.0, 1.1.12.0, 2020.3.15.1304, 4.0.2109.2802, 2.9.50.0, 1.0.5.0, 0.10.7.0, 21.1.2754, 28.2.18, 3.70.69, 3.31.107, 1.20.05, 2.02.34, 20.10.1, 1.6.238.16010, 8.0.6, 2.4.2, 4.1.4, 4.0.2, 1.9.6, 1.4.1, 1.3.0, 2.2.5, 1.16.116, 2.4.299, 1.20.16, 3.0.2001.801, 1.33.0, 2.48.9, 1.05.0, 1.19.4.0, 1.20.1, 1.4.0.2

Timeline

Official Publish: June 6th, 2022
Last Modified: July 9th, 2026
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.