[Japanese]
|
JVNDB-2009-000057
|
ATOK screen lock bypass vulnerability
|
ATOK from JustSystems Corporation contains a screen lock bypass vulnerability.
ATOK from JustSystems Corporation is a software for Japanese Kana-Kanji conversion. ATOK contains an issue with the restriction of launching external applications, which may lead to a screen lock bypass vulnerability.
Taku Kudo of Google Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 7.2 (High) [IPA Score]
- Access Vector: Local
- Access Complexity: Low
- Authentication: None
- Confidentiality Impact: Complete
- Integrity Impact: Complete
- Availability Impact: Complete
|
|
JustSystems Corporation
- ATOK (For more information, refer to the vendor's website)
- ATOK smile (For more information, refer to the vendor's website)
|
|
An attacker could execute arbitrary code or program with the privileges of the LocalSystem account.
|
[Update the Software]
Apply the applicable update according to the information provided by JustSystems.
|
JustSystems Corporation
|
- Permissions(CWE-264) [IPA Evaluation]
|
- CVE-2009-4738
|
- JVN : JVN#57040664
- National Vulnerability Database (NVD) : CVE-2009-4738
- IPA SECURITY ALERTS : Security Alert for Vulnerability in ATOK
|
- [2010/03/23]
Web page published
|