We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-47422



Description

Advanced Installer before 22.6 has an uncontrolled search path element local privilege escalation vulnerability. When running as SYSTEM in certain configurations, Advanced Installer looks in standard-user writable locations for non-existent binaries and executes them as SYSTEM. A low-privileged attacker can place a malicious binary in a targeted folder; when the installer is executed, the attacker achieves arbitrary SYSTEM code execution.

Reserved 2025-05-07 | Published 2025-07-08 | Updated 2025-07-08 | Assigner mitre

References

www.advancedinstaller.com/release-22.6.html

www.advancedinstaller.com/...curity-fixes-retrospective.html

cve.org (CVE-2025-47422)

nvd.nist.gov (CVE-2025-47422)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-47422

Support options

Helpdesk Chat, Email, Knowledgebase