VYPR
Unrated severityNVD Advisory· Published Apr 4, 2023· Updated Feb 18, 2025

CVE-2022-48225

CVE-2022-48225

Description

An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. It is used to install drivers from several different vendors. The Gemalto Document Reader child installation process is vulnerable to DLL hijacking, because it attempts to execute (with elevated privileges) multiple non-existent DLLs out of a non-existent standard-user writable location.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Acuant AcuFill SDK before 10.22.02.03 has a DLL hijacking flaw in the Gemalto Document Reader installer, allowing privilege escalation.

Vulnerability

Acuant AcuFill SDK before version 10.22.02.03 contains a DLL hijacking vulnerability during the installation of the Gemalto Document Reader child process. The installer attempts to load multiple non-existent DLLs from a standard-user writable directory, which does not exist by default. This allows an attacker to place a malicious DLL in that location to be executed with elevated privileges.

Exploitation

An attacker must have the ability to write files to the system (standard user privileges) and place a malicious DLL in the path where the installer looks for the missing DLLs. The Gemalto Document Reader installation runs with elevated privileges, so when it attempts to load the non-existent DLL, it will instead load the attacker's DLL from the writable directory. No user interaction beyond the normal installation process is required.

Impact

Successful exploitation grants the attacker arbitrary code execution in the context of the installer, which runs with elevated (SYSTEM) privileges. This can lead to full compromise of the affected system, including installation of malware, persistence, or unauthorized data access.

Mitigation

The vulnerability is fixed in Acuant AcuFill SDK version 10.22.02.03 and later [1]. Users should update to the latest version immediately. There is no workaround other than applying the patch, as the issue lies in the installer's loading behavior. No CISA KEV listing has been published at this time.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.