PT-2012-3159 · Justsystems · Just School+7

Naoto Katsumi

·

Published

2012-04-27

·

Updated

2017-12-14

·

CVE-2012-1242

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions JustSystems Ichitaro versions 2006 through 2011 JustSystems Ichitaro Government versions 2006 through 2010 JustSystems Ichitaro Portable with oreplug JustSystems Ichitaro Viewer JUST School JUST School versions 2009 and 2010 JUST Jump 4 JUST Frontier oreplug
Description The issue allows local users to gain privileges via a Trojan horse DLL in the current working directory due to an untrusted search path vulnerability.
Recommendations For JustSystems Ichitaro versions 2006 through 2011, consider restricting access to the current working directory to minimize the risk of exploitation. For JustSystems Ichitaro Government versions 2006 through 2010, avoid using the vulnerable software until a fix is available. For JustSystems Ichitaro Portable with oreplug, JustSystems Ichitaro Viewer, JUST School, JUST School versions 2009 and 2010, JUST Jump 4, JUST Frontier, and oreplug, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2012-1242

Affected Products

Just Frontier
Just Jump 4
Just School
Justsystems Ichitaro
Justsystems Ichitaro Government
Justsystems Ichitaro Portable
Justsystems Ichitaro Viewer
Oreplug