VYPR
Unrated severityNVD Advisory· Published Apr 4, 2023· Updated Feb 18, 2025

CVE-2022-48222

CVE-2022-48222

Description

An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During SDK installation, certutil.exe is called by the Acuant installer to install certificates. This window is not hidden, and is running with elevated privileges. A standard user can break out of this window, obtaining a full SYSTEM command prompt window. This results in complete compromise via arbitrary SYSTEM code execution (elevation of privileges).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Acuant AcuFill SDK installer allows a standard user to break out of a certutil.exe window running with SYSTEM privileges, leading to arbitrary code execution and full system compromise.

Vulnerability

An issue exists in the Acuant AcuFill SDK before version 10.22.02.03 [1]. During installation, the Acuant installer calls certutil.exe to install certificates [1]. This process is not hidden and runs with elevated privileges, leaving the command window visible and interactive [1].

Exploitation

A standard user can interact with the visible certutil.exe command window that is running with SYSTEM privileges [1]. By exploiting this interactive window, the attacker can break out of the intended process context, gaining access to a full SYSTEM command prompt [1]. This requires only that the user is present during the installation process and can interact with the window; no additional authentication or network access is needed [1].

Impact

Successful exploitation grants the attacker a SYSTEM command prompt, allowing arbitrary code execution at the highest privilege level on the system [1]. This results in complete compromise of the affected machine, including the ability to install programs, view or change data, and create new accounts with full administrative rights [1].

Mitigation

The vendor has addressed this vulnerability in Acuant AcuFill SDK version 10.22.02.03 and later [1]. Users should update to this or a newer version as soon as possible [1]. No workarounds are documented in the available references.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.