jvn.jp
https://jvn.jp/en/jp/JVN57749899 CVE-2024-47045
HIGH
Record summary
CVE-2024-47045 has a selected CVSS score of 7.8 (high).
Description
Privilege chaining issue exists in the installer of e-Tax software(common program). If this vulnerability is exploited, a malicious DLL prepared by an attacker may be executed with higher privileges than the application privilege.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 26, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
The installer of e-Tax software(common program)Browse National Tax Agency / The installer of e-Tax software(common program) | CVE List | All versions distributed on the NTA website before 2024 September 24 | affected |
Default status: unknown | CVE List | Before 3.0.18 | affected |
References
9jvn.jp
https://jvn.jp/en/jp/JVN78356367 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-47045 web116.jp
https://web116.jp/ced/support/version/broadband/500mi web116.jp
https://web116.jp/ced/support/version/broadband/600mi web116.jp
https://web116.jp/ced/support/version/broadband/pr_400mi web116.jp
https://web116.jp/ced/support/version/broadband/rt_400mi web116.jp
https://web116.jp/ced/support/version/broadband/rv_440mi e-tax.nta.go.jp
https://www.e-tax.nta.go.jp/topics/2024/topics_20240924_versionup.htm