---
id: CVE-2022-27438
title: >-
  Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the
  updater from Advanced Installer (Advanced Updater) are affected by a remote
  code execution vulnerability via the CustomDetection parameter in the update
  check…
summary: >-
  Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the
  updater from Advanced Installer (Advanced Updater) are affected by a remote
  code execution vulnerability via the CustomDetection parameter in the update
  check…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-494
vendor: caphyon
product: advanced_installer
affected:
  - advanced_installer < 19.4
  - call_flow_designer = 18.2.13
  - crm_template_generator = 2.1.23
  - boomtv_streamer_portal = 2.2.1
  - direct_folders = 4.0
  - teracopy = 3.8.5
  - emeditor = 21.3.0
  - flamory = 4.2.19.0
  - free_snipping_tool = 5.6.0.0
  - fxsound = 1.1.12.0
  - better_explorer = 2020.3.15.1304
  - gamecaster = 4.0.2109.2802
  - mailbird = 2.9.50.0
  - guzogo = 1.0.5.0
  - honeygain = 0.10.7.0
  - vi_package_manager = 21.1.2754
  - take_command = 28.2.18
  - archive_password_recovery = 3.70.69
  - asterisks_password_decryptor = 3.31.107
  - burning_suite = 1.20.05
  - rar_password_recovery = 3.70.69
  - volume_serial_number_editor = 2.02.34
  - zip_password_recovery = 3.70.69
  - password_agent = 20.10.1
  - scptoolkit = 1.6.238.16010
  - plagiarism_checker_x = 8.0.6
  - prusaslicer = 2.4.2
  - mycleanid = 4.1.4
  - mycleanpc = 4.0.2
  - mypasslock = 1.9.6
  - angry_birds_space = 1.4.1
  - bad_piggies = 1.3.0
  - displaylink_usb_graphics < 10.3.6400.0
  - urban_vpn = 2.2.5
  - vigembus_driver = 1.16.116
  - vpnhood = 2.4.299
  - virtual_desktop_streamer = 1.20.16
  - xsplit_express_video_editor = 3.0.2001.801
  - vw0420_firmware = 1.33.0
  - inclinalysis_digital_inclinometer = 2.48.9
  - ipi_utility = 1.05.0
  - rstar_rtu_host = 1.33.0
  - dt2011_firmware = 1.19.4.0
  - dt2011b_firmware = 1.19.4.0
  - dt2040_firmware = 1.19.4.0
  - dt2050_firmware = 1.19.4.0
  - dt2050b_firmware = 1.19.4.0
  - dt2055b_firmware = 1.19.4.0
  - dt2306_firmware = 1.19.4.0
  - dt2350_firmware = 1.19.4.0
  - dt2485_firmware = 1.19.4.0
  - dt4205_firmware = 1.19.4.0
  - dtsaa_firmware = 1.19.4.0
  - ic6560_firmware = 1.19.4.0
  - ic6660_firmware = 1.19.4.0
  - dtl201b/2b_firmware = 1.19.4.0
  - mtcm_firmware = 1.19.4.0
  - gaa2820_firmware = 1.19.4.0
  - rtu_firmware = 1.19.4.0
  - mems_tilt_meter_firmware = 1.20.1
  - portable_tilt_meter_firmware = 1.20.1
  - vw2106_firmware
  - th2016_firmware = 1.4.0.2
  - th2016b_firmware = 1.4.0.2
  - ma7_firmware = 1.4.0.2
  - qb120_firmware = 1.4.0.2
  - sg350_firmware = 1.4.0.2
  - ir420_firmware = 1.4.0.2
  - lp100_firmware = 1.4.0.2
  - c109_firmware = 1.4.0.2
patched:
  - advanced_installer 19.4
  - displaylink_usb_graphics 10.3.6400.0
published: '2022-06-06'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-27438'
references:
  - url: 'https://gerr.re/posts/cve-2022-27438/'
    label: cve@mitre.org
  - url: 'https://www.advancedinstaller.com/security-updates-auto-updater.html'
    label: cve@mitre.org
  - url: 'http://advanced.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://caphyon.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://gerr.re/posts/cve-2022-27438/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.advancedinstaller.com/security-updates-auto-updater.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.01976
epssPercentile: 0.79349
ingestedAt: '2026-07-06T17:03:24.406Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/gar-re/cve-2022-27438'
  checkedAt: '2026-09-21T15:25:20.110Z'
exploitAvailable: true
---

## Overview

Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.

## Affected

- `advanced_installer < 19.4`
- `call_flow_designer = 18.2.13`
- `crm_template_generator = 2.1.23`
- `boomtv_streamer_portal = 2.2.1`
- `direct_folders = 4.0`
- `teracopy = 3.8.5`
- `emeditor = 21.3.0`
- `flamory = 4.2.19.0`
- `free_snipping_tool = 5.6.0.0`
- `fxsound = 1.1.12.0`
- `better_explorer = 2020.3.15.1304`
- `gamecaster = 4.0.2109.2802`
- `mailbird = 2.9.50.0`
- `guzogo = 1.0.5.0`
- `honeygain = 0.10.7.0`
- `vi_package_manager = 21.1.2754`
- `take_command = 28.2.18`
- `archive_password_recovery = 3.70.69`
- `asterisks_password_decryptor = 3.31.107`
- `burning_suite = 1.20.05`
- `rar_password_recovery = 3.70.69`
- `volume_serial_number_editor = 2.02.34`
- `zip_password_recovery = 3.70.69`
- `password_agent = 20.10.1`
- `scptoolkit = 1.6.238.16010`
- `plagiarism_checker_x = 8.0.6`
- `prusaslicer = 2.4.2`
- `mycleanid = 4.1.4`
- `mycleanpc = 4.0.2`
- `mypasslock = 1.9.6`
- `angry_birds_space = 1.4.1`
- `bad_piggies = 1.3.0`
- `displaylink_usb_graphics < 10.3.6400.0`
- `urban_vpn = 2.2.5`
- `vigembus_driver = 1.16.116`
- `vpnhood = 2.4.299`
- `virtual_desktop_streamer = 1.20.16`
- `xsplit_express_video_editor = 3.0.2001.801`
- `vw0420_firmware = 1.33.0`
- `inclinalysis_digital_inclinometer = 2.48.9`
- `ipi_utility = 1.05.0`
- `rstar_rtu_host = 1.33.0`
- `dt2011_firmware = 1.19.4.0`
- `dt2011b_firmware = 1.19.4.0`
- `dt2040_firmware = 1.19.4.0`
- `dt2050_firmware = 1.19.4.0`
- `dt2050b_firmware = 1.19.4.0`
- `dt2055b_firmware = 1.19.4.0`
- `dt2306_firmware = 1.19.4.0`
- `dt2350_firmware = 1.19.4.0`
- `dt2485_firmware = 1.19.4.0`
- `dt4205_firmware = 1.19.4.0`
- `dtsaa_firmware = 1.19.4.0`
- `ic6560_firmware = 1.19.4.0`
- `ic6660_firmware = 1.19.4.0`
- `dtl201b/2b_firmware = 1.19.4.0`
- `mtcm_firmware = 1.19.4.0`
- `gaa2820_firmware = 1.19.4.0`
- `rtu_firmware = 1.19.4.0`
- `mems_tilt_meter_firmware = 1.20.1`
- `portable_tilt_meter_firmware = 1.20.1`
- `vw2106_firmware`
- `th2016_firmware = 1.4.0.2`
- `th2016b_firmware = 1.4.0.2`
- `ma7_firmware = 1.4.0.2`
- `qb120_firmware = 1.4.0.2`
- `sg350_firmware = 1.4.0.2`
- `ir420_firmware = 1.4.0.2`
- `lp100_firmware = 1.4.0.2`
- `c109_firmware = 1.4.0.2`

## Remediation

Upgrade past the affected range:

- `advanced_installer 19.4`
- `displaylink_usb_graphics 10.3.6400.0`
