CRITICAL · 9.8

CVE-2022-36344

An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affe...

Vulnerability Description

An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of the Windows service if it is placed in a certain path. Affected products are bundled with the following product series: Office and Office Integrated Software, ATOK, Hanako, JUST PDF, Shuriken, Homepage Builder, JUST School, JUST Smile Class, JUST Smile, JUST Frontier, JUST Jump, and Tri-De DetaProtect.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
JustsystemsAtok Medical 2All versions
JustsystemsAtok Medical 3All versions
JustsystemsAtok Pro 3All versions
JustsystemsAtok Pro 4All versions
JustsystemsAtok Pro 5All versions
JustsystemsHanako Police 5All versions
JustsystemsHanako Police 6All versions
JustsystemsHanako Police 7All versions
JustsystemsHanako Pro 3All versions
JustsystemsHanako Pro 4All versions
JustsystemsHanako Pro 5All versions
JustsystemsHomepage Builder 20All versions
JustsystemsHomepage Builder 21All versions
JustsystemsHomepage Builder 22All versions
JustsystemsIchitaro Government 10All versions
JustsystemsIchitaro Government 8-
JustsystemsIchitaro Government 9All versions
JustsystemsIchitaro Pro 3All versions
JustsystemsIchitaro Pro 4All versions
JustsystemsIchitaro Pro 5All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-36344?

CVE-2022-36344 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affe...

How severe is CVE-2022-36344?

CVE-2022-36344 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2022-36344?

Check the references section above for vendor advisories and patch information. Affected products include: Justsystems Atok Medical 2, Justsystems Atok Medical 3, Justsystems Atok Pro 3, Justsystems Atok Pro 4, Justsystems Atok Pro 5.