PT-2023-30811 · Unknown · Jcicsecuritytool

·

CVE-2023-48387

·

Publicado

2023-12-15

·

Atualizado

2024-10-14

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JCICSecurityTool (affected versions not specified)
Description The issue arises from the JCICSecurityTool's failure to check the source website and access locations when executing multiple Registry-related functions. If a user, who has completed identity verification, browses a malicious webpage, an attacker can exploit this to read or modify any registry file under HKEY CURRENT USER, achieving remote code execution. The tool's Registry-related functions also have insufficient filtering for special characters, allowing an unauthenticated remote attacker to inject malicious scripts into a webpage.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-48387

Produtos afetados

Jcicsecuritytool