[Japanese]

JVNDB-2022-000099

Corel Roxio Creator LJB starts a program with an unquoted file path

Overview

Roxio Creator LJB provided by Corel Corporation starts another program with an unquoted file path (CWE-428).

Haruka Hino of LAC Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 8.2 (High) [IPA Score]
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Scope: Changed
  • Confidentiality Impact: High
  • Integrity Impact: High
  • Availability Impact: High
CVSS V2 Severity:
Base Metrics 6.8 (Medium) [IPA Score]
  • Access Vector: Local
  • Access Complexity: Low
  • Authentication: Single Instance
  • Confidentiality Impact: Complete
  • Integrity Impact: Complete
  • Availability Impact: Complete
Affected Products

Roxio Creator LJB bundled with the computers provided by Fujitsu Client Computing Ltd. for corporate users is affected. The affected software versions and builds numbers are as follows:

Corel Corporation
  • Roxio Creator LJB version number: 12.2, build number: 106B62B
  • Roxio Creator LJB version number: 12.2, build number: 106B63A
  • Roxio Creator LJB version number: 12.2, build number: 106B69A
  • Roxio Creator LJB version number: 12.2, build number: 106B71A
  • Roxio Creator LJB version number: 12.2, build number: 106B74A

Impact

Since a registered Windows service path contains spaces and are unquoted, if a malicious executable is placed on a certain path, the executable may be executed with the privilege of the Windows service.
Solution

[Update the software]
Update the software to the latest version according to the information provided by the developer.
Vendor Information

FUJITSU
CWE (What is CWE?)

  1. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2022-46662
References

  1. JVN : JVN#13075438
  2. Related document : Roxio Creator LJB Update Program (Fujitsu Client Computing Made Computer Bundle-Only)
Revision History

  • [2022/12/19]
      Web page was published