PT-2023-30811 · Unknown · Jcicsecuritytool
Angelboy
·
Published
2023-12-15
·
Updated
2024-10-14
·
CVE-2023-48387
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JCICSecurityTool (affected versions not specified)
Description
The issue arises from the JCICSecurityTool's failure to check the source website and access locations when executing multiple Registry-related functions. If a user, who has completed identity verification, browses a malicious webpage, an attacker can exploit this to read or modify any registry file under HKEY CURRENT USER, achieving remote code execution. The tool's Registry-related functions also have insufficient filtering for special characters, allowing an unauthenticated remote attacker to inject malicious scripts into a webpage.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jcicsecuritytool