← Back

CVE-2018-0624

nvd nist
Published: Sep 7, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Untrusted search path vulnerability in Multiple Yayoi 17 Series products (Yayoi Kaikei 17 Series Ver.23.1.1 and earlier, Yayoi Aoiro Shinkoku 17 Ver.23.1.1 and earlier, Yayoi Kyuuyo 17 Ver.20.1.4 and earlier, Yayoi Kyuuyo Keisan 17 Ver.20.1.4 and earlier, Yayoi Hanbai 17 Series Ver.20.0.2 and earlier, and Yayoi Kokyaku Kanri 17 Ver.11.0.2 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. This flaw exists within the handling of ykkapi.dll loaded by the vulnerable products.

Affected (6)

6 products
Aoiro Shinkoku
Hanbai
Kaikei
Kokyaku Kanri
Kyuuyo
Kyuuyo Keisan
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Up to 23.1.1
Up to 20.0.2
Up to 23.1.1
Up to 11.0.2
Up to 20.1.4
Up to 20.1.4

References (2)

Source: vultures@jpcert.or.jp
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.