CVE-2022-27438 is a remote code execution vulnerability affecting Caphyon Ltd Advanced Installer 19.3 and earlier, as well as third-party products that embed or use the Advanced Installer updater component (Advanced Updater). The flaw is in the update check functionality and is triggered through the CustomDetection parameter. When an affected installation is started and performs an update check, attacker-controlled input delivered via CustomDetection can lead to execution of arbitrary code. The issue therefore extends beyond the Advanced Installer product itself to software packages that ship with the vulnerable updater component.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept exploit for CVE-2022-27438, a remote code execution vulnerability in Caphyon Ltd Advanced Installer 19.3's update mechanism. The exploit consists of a Python script ('cve-2022-27438_poc.py') that runs an HTTPS server mimicking the legitimate update server (www.advancedinstaller.com). The attacker must redirect the target's update requests to their server, typically by editing the hosts file or using DNS spoofing. The server responds to update configuration requests with a malicious config that instructs the updater to execute arbitrary commands (in this POC, launching calc.exe via cmd.exe). The repository also includes a README.md with detailed setup and exploitation instructions. The exploit demonstrates remote code execution as the current user when the update process is triggered, requiring some attacker-controlled network configuration and a valid SSL certificate for the spoofed domain.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.