VYPR
Unrated severityNVD Advisory· Published Apr 4, 2023· Updated Feb 13, 2025

CVE-2022-48226

CVE-2022-48226

Description

An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During installation, an EXE gets executed out of C:\Windows\Temp. A standard user can create the path file ahead of time and obtain elevated code execution. Permissions need to be modified to prevent manipulation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Acuant AcuFill SDK before 10.22.02.03 allows a standard user to gain elevated code execution by pre-creating a file in C:\Windows\Temp during installation.

Vulnerability

An issue exists in Acuant AcuFill SDK versions prior to 10.22.02.03. During the installation process, an executable is executed from the C:\Windows\Temp directory. A standard user can pre-create the expected file or directory at that location, allowing them to hijack the execution flow. The vulnerability is present in all versions before the fixed release [1].

Exploitation

An attacker requires local access as a standard user. They can create a file or directory at C:\Windows\Temp that matches the name expected by the installer. When the installation runs, the executable is launched from that attacker-controlled location, running with elevated privileges (typically SYSTEM). No additional user interaction is needed beyond the normal installation process [1].

Impact

Successful exploitation results in arbitrary code execution with elevated privileges, leading to full system compromise. The attacker gains the ability to install programs, modify data, or create new accounts with full user rights. This is a privilege escalation vulnerability [1].

Mitigation

The vulnerability is fixed in Acuant AcuFill SDK version 10.22.02.03. Users should update to this version or later. If immediate patching is not possible, restrict standard user write access to C:\Windows\Temp as a workaround, though this may affect other applications. The vendor (GBG/Acuant) has released the fix; no CISA KEV listing is currently available [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.