An issue was discovered in Acuant AcuFill SDK before 10...
High severity
Unreviewed
Published
Apr 4, 2023
to the GitHub Advisory Database
•
Updated Apr 19, 2023
Description
Published by the National Vulnerability Database
Apr 4, 2023
Published to the GitHub Advisory Database
Apr 4, 2023
Last updated
Apr 19, 2023
An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. Multiple MSI's get executed out of a standard-user writable directory. Through a race condition and OpLock manipulation, these files can be overwritten by a standard user. They then get executed by the elevated installer. This gives a standard user full SYSTEM code execution (elevation of privileges).
References