[Japanese] | |
JVNDB-2017-000201 | |
Installer of Shin Kinkyuji Houkoku Data Nyuryoku Program may insecurely load Dynamic Link Libraries | |
Overview | |
Installer of Shin Kinkyuji Houkoku Data Nyuryoku Program provided by Agency for Natural Resources and Energy of METI contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 7.8 (High) [IPA Score]
CVSS V2 Severity:
Base Metrics 6.8 (Medium) [IPA Score]
| |
Affected Products | |
| |
Agency for Natural Resources and Energy of Ministry of Economy,Trade and Industry (METI) | |
| |
Impact | |
Arbitrary code may be executed with the privilege of the user invoking the installer. | |
Solution | |
[Use the latest installer] | |
Vendor Information | |
Agency for Natural Resources and Energy of Ministry of Economy,Trade and Industry (METI) | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2017/08/17 |
Date First Published | 2017/08/17 |
Date Last Updated | 2018/02/14 |