[Japanese]

JVNDB-2024-000115

Chatwork Desktop Application (Windows) uses a potentially dangerous function

Overview

Chatwork Desktop Application (Windows) provided by kubell Co., Ltd. contains an issue with use of potentially dangerous function (CWE-676), which allows a user to access an external website via a link in the application.

RyotaK of Flatt Security Inc. directly reported this vulnerability to the developer and coordinated. After the coordination was completed, the developer reported this case to IPA under Information Security Early Warning Partnership to notify the users of the solution through JVN, and JPCERT/CC coordinated with the developer for JVN advisory publication.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 5.5 (Medium) [IPA Score]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: Required
  • Scope: Unchanged
  • Confidentiality Impact: Low
  • Integrity Impact: Low
  • Availability Impact: Low
Affected Products


kubell Co., Ltd.
  • Chatwork Desktop Application for Windows versions prior to 2.9.2

Impact

If a user clicks a specially crafted link in the application, an arbitrary file may be downloaded from an external website and executed. As a result, arbitrary code may be executed on the device that runs Chatwork Desktop Application (Windows).
Solution

[Update the application]
Update the application to the latest version according to the information provided by the developer.

[Apply the workaround]
The developer states that the impacts of this vulnerability may be mitigated by disabling guest access of Windows OS SMB client function.

For more information, refer to the information provided by the developer.
Vendor Information

kubell Co., Ltd.
CWE (What is CWE?)

  1. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2024-50307
References

  1. JVN : JVN#78335885
Revision History

  • [2024/10/28]
      Web page was published