Insecure Permissions in Acuant AcuFill SDK Allows Arbitrary Code Execution

Insecure Permissions in Acuant AcuFill SDK Allows Arbitrary Code Execution

CVE-2022-48224 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. It is installed with insecure permissions (full write access within Program Files). Standard users can replace files within this directory that get executed with elevated privileges, leading to a complete arbitrary code execution (elevation of privileges).

Learn more about our User Device Pen Test.