Privilege chaining issue exists in the installer of e-Tax software(common program). If this vulnerability is exploited, a malicious DLL prepared by an attacker may be executed with higher privileges than the application privilege.
History

Thu, 26 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared E-tax.nta
E-tax.nta e-tax
CPEs cpe:2.3:a:e-tax.nta:e-tax:*:*:*:*:*:*:*:*
Vendors & Products E-tax.nta
E-tax.nta e-tax
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 26 Sep 2024 07:30:00 +0000


Thu, 26 Sep 2024 06:45:00 +0000

Type Values Removed Values Added
Description User interface (UI) misrepresentation of critical information issue exists in multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION. If this vulnerability is exploited, an attacker who identified WAN-side IPv6 address may access the product's Device Setting page via WAN-side. Note that, affects products are also provided by NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION, but the vulnerability only affects products subscribed and used in NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION areas. Privilege chaining issue exists in the installer of e-Tax software(common program). If this vulnerability is exploited, a malicious DLL prepared by an attacker may be executed with higher privileges than the application privilege.
Weaknesses CWE-268
References

Thu, 26 Sep 2024 03:45:00 +0000

Type Values Removed Values Added
Description User interface (UI) misrepresentation of critical information issue exists in multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION. If this vulnerability is exploited, an attacker who identified WAN-side IPv6 address may access the product's Device Setting page via WAN-side. Note that, affects products are also provided by NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION, but the vulnerability only affects products subscribed and used in NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION areas.
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2024-09-26T03:33:48.931Z

Updated: 2024-09-26T14:45:34.542Z

Reserved: 2024-09-17T05:33:19.502Z

Link: CVE-2024-47045

cve-icon Vulnrichment

Updated: 2024-09-26T14:45:17.889Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-26T04:15:07.657

Modified: 2024-09-26T15:35:29.950

Link: CVE-2024-47045

cve-icon Redhat

No data.