Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x8rm-c2pf-m49v

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

Untrusted search path vulnerability in installers for The Public Certification Service for Individuals "The JPKI user's software (for Windows 7 and later)" Ver3.1 and earlier, The Public Certification Service for Individuals "The JPKI user's software (for Windows Vista)", The Public Certification Service for Individuals "The JPKI user's software" Ver2.6 and earlier that were available until April 27, 2017 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

Untrusted search path vulnerability in installers for The Public Certification Service for Individuals "The JPKI user's software (for Windows 7 and later)" Ver3.1 and earlier, The Public Certification Service for Individuals "The JPKI user's software (for Windows Vista)", The Public Certification Service for Individuals "The JPKI user's software" Ver2.6 and earlier that were available until April 27, 2017 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

EPSS

Процентиль: 37%
0.00163
Низкий

7.3 High

CVSS3

Дефекты

CWE-426

Связанные уязвимости

CVSS3: 7.3
nvd
больше 8 лет назад

Untrusted search path vulnerability in installers for The Public Certification Service for Individuals "The JPKI user's software (for Windows 7 and later)" Ver3.1 and earlier, The Public Certification Service for Individuals "The JPKI user's software (for Windows Vista)", The Public Certification Service for Individuals "The JPKI user's software" Ver2.6 and earlier that were available until April 27, 2017 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

EPSS

Процентиль: 37%
0.00163
Низкий

7.3 High

CVSS3

Дефекты

CWE-426