PT-2017-11529 · Unknown · Shin Kikan Toukei Houkoku Data Nyuryokuyou Program

Eili Masami

·

Published

2017-08-18

·

Updated

2017-08-24

·

CVE-2017-10821

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Shin Kikan Toukei Houkoku Data Nyuryokuyou Program version released on 2013 September 30
Description The issue is related to an untrusted search path vulnerability in the Installer for the program. This allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Recommendations For the version released on 2013 September 30, consider restricting access to the Installer until a fix is available, and avoid using the Installer in environments where a Trojan horse DLL could be introduced. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-10821

Affected Products

Shin Kikan Toukei Houkoku Data Nyuryokuyou Program