Impact
CorvusSKK includes an integer overflow flaw that can be triggered by malicious input, allowing an attacker to overwrite data in a dictionary file. The vulnerability may enable unauthorized modification of application data, potentially compromising program configuration or local persistence. The impact is limited to data integrity rather than full system compromise, as no remote code execution or privilege escalation is described.
Affected Systems
SASAKI Nobuyuki CorvusSKK is affected. No specific version information is cited, so all current releases of CorvusSKK could be vulnerable until a fix is applied.
Risk and Exploitability
The CVSS score of 4.6 indicates low to moderate risk. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation activity. The likely attack vector is local or requires the application to process crafted input; no evidence of remote exploitation is provided. Overall risk is comparatively low, but the ability to alter configuration files warrants attention.
OpenCVE Enrichment