PT-2023-30811 · Unknown · Jcicsecuritytool

Angelboy

·

Published

2023-12-15

·

Updated

2024-10-14

·

CVE-2023-48387

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JCICSecurityTool (affected versions not specified)
Description The issue arises from the JCICSecurityTool's failure to check the source website and access locations when executing multiple Registry-related functions. If a user, who has completed identity verification, browses a malicious webpage, an attacker can exploit this to read or modify any registry file under HKEY CURRENT USER, achieving remote code execution. The tool's Registry-related functions also have insufficient filtering for special characters, allowing an unauthenticated remote attacker to inject malicious scripts into a webpage.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2023-48387

Affected Products

Jcicsecuritytool