CVE-2022-48226: Gbgplc Acuant Acufill SDK

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During installation, an EXE gets executed out of C:\Windows\Temp. A standard user can create the path file ahead of time and obtain elevated code execution. Permissions need to be modified to prevent manipulation.

Affected products

  • Gbgplc Acuant Acufill SDK: before 10.22.02.03 (fixed in 10.22.02.03)

Published 2023-04-04. Last modified 2026-06-17.