ZeroHour

CVE-2023-38128

PoC ×2
CVSS 3.1
7.8 high
EPSS
<1%p50
Published
()
Modified
Description

An out-of-bounds write vulnerability exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause a type confusion, which can lead to memory corruption and eventually arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

Vendors
justsystems
Products
easy postcard max, ichitaro 2021, ichitaro 2022, ichitaro 2023, ichitaro government 10, ichitaro government 8, ichitaro government 9, ichitaro pro 3, ichitaro pro 4, ichitaro pro 5, just government 3, just government 4
Weakness
CWE-843, CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news