[Japanese] | |
JVNDB-2021-000018 | |
The installers of E START products may insecurely load Dynamic Link Libraries | |
Overview | |
The installers of E START products by GMO INSIGHT Inc. contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries in the folder specified by the TEMP environment variable or where the installer resides (CWE-427, CVE-2015-9267, and CVE-2015-9268). | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 7.8 (High) [IPA Score]
CVSS V2 Severity:
Base Metrics 6.8 (Medium) [IPA Score]
| |
Affected Products | |
| |
GMO insight Inc. | |
| |
Impact | |
Arbitrary code may be executed with the privilege of the user invoking the installer. | |
Solution | |
[Use the latest installer] | |
Vendor Information | |
GMO insight Inc. | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2021/03/05 |
Date First Published | 2021/03/05 |
Date Last Updated | 2023/11/16 |