CVE-2017-10870

UnknownEPSS 1.31%

Last modified

CVE-2017-10870 is a vulnerability of currently unknown severity. Memory corruption vulnerability in Rakuraku Hagaki (Rakuraku Hagaki 2018, Rakuraku Hagaki 2017, Rakuraku Hagaki 2016) and Rakuraku Hagaki Select for Ichitaro (Ichitaro 2017, Ichitaro 2016, Ichitaro 2015, Ichitaro Pro3, Ichitaro Pro2, Ichitaro Pro, Ichitaro 2011, Ichitaro Government 8, Ichitaro Government 7, Ichitaro Government 6 and Ichitaro 2017 Trial version) allows attackers to execute arbitrary code with privileges of the application via specially crafted file.. EPSS estimates a 1.31% chance of exploitation in the next 30 days.

Description

Memory corruption vulnerability in Rakuraku Hagaki (Rakuraku Hagaki 2018, Rakuraku Hagaki 2017, Rakuraku Hagaki 2016) and Rakuraku Hagaki Select for Ichitaro (Ichitaro 2017, Ichitaro 2016, Ichitaro 2015, Ichitaro Pro3, Ichitaro Pro2, Ichitaro Pro, Ichitaro 2011, Ichitaro Government 8, Ichitaro Government 7, Ichitaro Government 6 and Ichitaro 2017 Trial version) allows attackers to execute arbitrary code with privileges of the application via specially crafted file.

Metrics

EPSS Probability
1.31%

67.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
JustsystemsEasy Postcard 2016All versions
JustsystemsEasy Postcard 2017All versions
JustsystemsEasy Postcard 2018All versions
JustsystemsIchitaro 2016All versions
JustsystemsIchitaro 2017All versions
JustsystemsIchitaro 2017 Trial VersionAll versions
JustsystemsIchitaro 2018All versions
JustsystemsIchitaro Government 6All versions
JustsystemsIchitaro Government 7All versions
JustsystemsIchitaro Government 8All versions
JustsystemsIchitaro ProAll versions
JustsystemsIchitaro Pro 2All versions
JustsystemsIchitaro Pro 2011All versions
JustsystemsIchitaro Pro 3All versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-10870?
Memory corruption vulnerability in Rakuraku Hagaki (Rakuraku Hagaki 2018, Rakuraku Hagaki 2017, Rakuraku Hagaki 2016) and Rakuraku Hagaki Select for Ichitaro (Ichitaro 2017, Ichitaro 2016, Ichitaro 2015, Ichitaro Pro3, Ichitaro Pro2, Ichitaro Pro, Ichitaro 2011, Ichitaro Government 8, Ichitaro Government 7, Ichitaro Government 6 and Ichitaro 2017 Trial version) allows attackers to execute arbitrary code with privileges of the application via specially crafted file.
How severe is CVE-2017-10870?
Severity scoring for CVE-2017-10870 is pending analysis. The EPSS model estimates a 1.31% probability of exploitation in the next 30 days.
How do I fix CVE-2017-10870?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-10870?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST