CVE-2022-27438High· 8.1▾ MidnightPoC availableCaphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 44.6 · likelihood 0.4 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.4%
1 GitHub repo
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.
advanced_installer < 19.4call_flow_designer = 18.2.13crm_template_generator = 2.1.23boomtv_streamer_portal = 2.2.1direct_folders = 4.0teracopy = 3.8.5emeditor = 21.3.0flamory = 4.2.19.0free_snipping_tool = 5.6.0.0fxsound = 1.1.12.0better_explorer = 2020.3.15.1304gamecaster = 4.0.2109.2802mailbird = 2.9.50.0guzogo = 1.0.5.0honeygain = 0.10.7.0vi_package_manager = 21.1.2754take_command = 28.2.18archive_password_recovery = 3.70.69asterisks_password_decryptor = 3.31.107burning_suite = 1.20.05rar_password_recovery = 3.70.69volume_serial_number_editor = 2.02.34zip_password_recovery = 3.70.69password_agent = 20.10.1scptoolkit = 1.6.238.16010plagiarism_checker_x = 8.0.6prusaslicer = 2.4.2mycleanid = 4.1.4mycleanpc = 4.0.2mypasslock = 1.9.6angry_birds_space = 1.4.1bad_piggies = 1.3.0displaylink_usb_graphics < 10.3.6400.0urban_vpn = 2.2.5vigembus_driver = 1.16.116vpnhood = 2.4.299virtual_desktop_streamer = 1.20.16xsplit_express_video_editor = 3.0.2001.801vw0420_firmware = 1.33.0inclinalysis_digital_inclinometer = 2.48.9ipi_utility = 1.05.0rstar_rtu_host = 1.33.0dt2011_firmware = 1.19.4.0dt2011b_firmware = 1.19.4.0dt2040_firmware = 1.19.4.0dt2050_firmware = 1.19.4.0dt2050b_firmware = 1.19.4.0dt2055b_firmware = 1.19.4.0dt2306_firmware = 1.19.4.0dt2350_firmware = 1.19.4.0dt2485_firmware = 1.19.4.0dt4205_firmware = 1.19.4.0dtsaa_firmware = 1.19.4.0ic6560_firmware = 1.19.4.0ic6660_firmware = 1.19.4.0dtl201b/2b_firmware = 1.19.4.0mtcm_firmware = 1.19.4.0gaa2820_firmware = 1.19.4.0rtu_firmware = 1.19.4.0mems_tilt_meter_firmware = 1.20.1portable_tilt_meter_firmware = 1.20.1vw2106_firmwareth2016_firmware = 1.4.0.2th2016b_firmware = 1.4.0.2ma7_firmware = 1.4.0.2qb120_firmware = 1.4.0.2sg350_firmware = 1.4.0.2ir420_firmware = 1.4.0.2lp100_firmware = 1.4.0.2c109_firmware = 1.4.0.2Upgrade past the affected range:
advanced_installer 19.4displaylink_usb_graphics 10.3.6400.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-24140Medium· 6.6IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP requests in their update procedure in order to download a config file
CVE-2026-93534Medium· 6.3A vulnerability was identified in spatie Scotty up to 1.4.2
CVE-2026-7006High· 7.3Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged local attackers to execute arbitrary code with elevated privileges …
CVE-2026-48046Critical· 9.3Streambert is a cross-platform Electron Desktop App to stream and download video content
CVE-2022-24644High· 8.8ZZ Inc
CVE-2022-28944High· 8.8Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check