Description
An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of the Windows service if it is placed in a certain path. Affected products are bundled with the following product series: Office and Office Integrated Software, ATOK, Hanako, JUST PDF, Shuriken, Homepage Builder, JUST School, JUST Smile Class, JUST Smile, JUST Frontier, JUST Jump, and Tri-De DetaProtect.
Published: 2022-08-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-39060 An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of the Windows service if it is placed in a certain path. Affected products are bundled with the following product series: Office and Office Integrated Software, ATOK, Hanako, JUST PDF, Shuriken, Homepage Builder, JUST School, JUST Smile Class, JUST Smile, JUST Frontier, JUST Jump, and Tri-De DetaProtect.
History

No history.

Subscriptions

Justsystems Atok Medical 2 Atok Medical 3 Atok Pro 3 Atok Pro 4 Atok Pro 5 Hanako Police 5 Hanako Police 6 Hanako Police 7 Hanako Pro 3 Hanako Pro 4 Hanako Pro 5 Homepage Builder 20 Homepage Builder 21 Homepage Builder 22 Ichitaro Government 10 Ichitaro Government 8 Ichitaro Government 9 Ichitaro Pro 3 Ichitaro Pro 4 Ichitaro Pro 5 Just Calc 3 Just Calc 4 Just Calc 5 Just Focus 3 Just Focus 4 Just Frontier 3 Just Government 2 Just Government 3 Just Government 4 Just Government 5 Just Jump 8 Just Jump Class Just Jump Class 2 Just Medical 2 Just Medical 3 Just Medical 4 Just Medical 5 Just Note 3 Just Note 4 Just Note 5 Just Office 2 Just Office 3 Just Office 4 Just Office 5 Just Pdf 3 Just Pdf 4 Just Pdf 5 Just Police 2 Just Police 3 Just Police 4 Just Police 5 Just School 6 Just School 7 Just Smile 6 Just Smile 7 Just Smile 8 Just Smile Class 2 Shuriken Pro 6 Shuriken Pro 7 Tri-de Dataprotect
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-08-03T10:00:04.308Z

Reserved: 2022-07-22T00:00:00.000Z

Link: CVE-2022-36344

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-08-16T08:15:09.157

Modified: 2024-11-21T07:12:49.830

Link: CVE-2022-36344

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses