CVE-2022-36344

An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of the Windows service if it is placed in a certain path. Affected products are bundled with the following product series: Office and Office Integrated Software, ATOK, Hanako, JUST PDF, Shuriken, Homepage Builder, JUST School, JUST Smile Class, JUST Smile, JUST Frontier, JUST Jump, and Tri-De DetaProtect.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
jpcertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
VendorProductVersion
justsystemsatok_medical_2
*
justsystemsatok_medical_3
*
justsystemsatok_pro_3
*
justsystemsatok_pro_4
*
justsystemsatok_pro_5
*
justsystemshanako_police_5
*
justsystemshanako_police_6
*
justsystemshanako_police_7
*
justsystemshanako_pro_3
*
justsystemshanako_pro_4
*
justsystemshanako_pro_5
*
justsystemshomepage_builder_20
*
justsystemshomepage_builder_21
*
justsystemshomepage_builder_22
*
justsystemsichitaro_government_10
*
justsystemsichitaro_government_8
-
justsystemsichitaro_government_9
*
justsystemsichitaro_pro_3
*
justsystemsichitaro_pro_4
*
justsystemsichitaro_pro_5
*
justsystemsjust_calc_3
*
justsystemsjust_calc_4
*
justsystemsjust_calc_5
*
justsystemsjust_focus_3
*
justsystemsjust_focus_4
*
justsystemsjust_frontier_3
*
justsystemsjust_government_2
*
justsystemsjust_government_3
*
justsystemsjust_government_4
*
justsystemsjust_government_5
*
justsystemsjust_jump_8
*
justsystemsjust_jump_class
*
justsystemsjust_jump_class_2
*
justsystemsjust_medical_2
*
justsystemsjust_medical_3
*
justsystemsjust_medical_4
*
justsystemsjust_medical_5
*
justsystemsjust_note_3
*
justsystemsjust_note_4
*
justsystemsjust_note_5
*
justsystemsjust_office_2
*
justsystemsjust_office_3
*
justsystemsjust_office_4
*
justsystemsjust_office_5
*
justsystemsjust_pdf_3
*
justsystemsjust_pdf_4
*
justsystemsjust_pdf_5
*
justsystemsjust_pdf_5
*
justsystemsjust_police_2
*
justsystemsjust_police_3
*
justsystemsjust_police_4
*
justsystemsjust_police_5
*
justsystemsjust_school_6
*
justsystemsjust_school_7
*
justsystemsjust_smile_6
*
justsystemsjust_smile_7
*
justsystemsjust_smile_8
*
justsystemsjust_smile_class_2
*
justsystemsshuriken_pro_6
*
justsystemsshuriken_pro_7
*
justsystemstri-de_dataprotect
*
𝑥
= Vulnerable software versions