[Japanese] | |
JVNDB-2017-000101 | |
Installers of the screensavers provided by JAPAN AIR SELF DEFENSE FORCE, MINISTRY OF DEFENSE may insecurely load Dynamic Link Libraries | |
Overview | |
Installers of the screensavers provided by JAPAN AIR SELF DEFENSE FORCE, MINISTRY OF DEFENSE contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 7.8 (High) [IPA Score]
CVSS V2 Severity:
Base Metrics 6.8 (Medium) [IPA Score]
| |
Affected Products | |
| |
Japan Air Self-Defense Force (JASDF) | |
Following installers of the screensavers provided by JAPAN AIR SELF DEFENSE FORCE, MINISTRY OF DEFENSE are affected by this vulnerability: * clock_01_setup.exe * clock_02_setup.exe * jasdf_01.exe * jasdf_02.exe * jasdf_03.exe * jasdf_04.exe * jasdf_05.exe * scramble_setup.exe | |
Impact | |
This vulnerability can be exploited when the following condition is met. If this vulnerability is exploited, arbitrary code may be executed with the privilege of the user invoking the installer. | |
Solution | |
[Do not install the screensavers] | |
Vendor Information | |
Japan Air Self-Defense Force (JASDF) | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2017/05/25 |
Date First Published | 2017/05/25 |
Date Last Updated | 2018/02/15 |