CVE-2017-2231

HIGH

MLIT DenshiSeikabutsuSakuseiShienKensa <3.02 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Untrusted search path vulnerability in The installer of MLIT DenshiSeikabutsuSakuseiShienKensa system Ver3.02 and earlier, distributed till June 20, 2017, The self-extracting archive including the installer of MLIT DenshiSeikabutsuSakuseiShienKensa system Ver3.02 and earlier, distributed till June 20, 2017 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN06337557/index.html
Vendor Advisory x_refsource_misc
http://www.mlit.go.jp/common/001189444.pdf

Scores

CVSS v3 7.8
EPSS 0.0123
EPSS Percentile 65.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-426
Status published
Products (3)
Ministry of Land, Infrastructure, Transport and Tourism, Japan/The installer of MLIT DenshiSeikabutsuSakuseiShienKensa system Ver3.02 and earlier, distributed till June 20, 2017
Ministry of Land, Infrastructure, Transport and Tourism, Japan/The self-extracting archive including the installer of MLIT DenshiSeikabutsuSakuseiShienKensa system Ver3.02 and earlier, distributed till June 20, 2017
mlit/denshiseikabutsusakuseishienkensa < 3.02
Published Jul 07, 2017
Tracked Since Feb 18, 2026