PT-2023-30811 · Unknown · Jcicsecuritytool
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JCICSecurityTool (affected versions not specified)
Description
The issue arises from the JCICSecurityTool's failure to check the source website and access locations when executing multiple Registry-related functions. If a user, who has completed identity verification, browses a malicious webpage, an attacker can exploit this to read or modify any registry file under HKEY CURRENT USER, achieving remote code execution. The tool's Registry-related functions also have insufficient filtering for special characters, allowing an unauthenticated remote attacker to inject malicious scripts into a webpage.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jcicsecuritytool