CVE-2023-38127

HIGHCVSS 7.8/10EPSS 0.65%

Last modified

CVE-2023-38127 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause the parser to make an under-sized allocation, which can later allow for memory corruption, potentially resulting in arbitrary code execution. EPSS estimates a 0.65% chance of exploitation in the next 30 days.

Description

An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause the parser to make an under-sized allocation, which can later allow for memory corruption, potentially resulting in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Probability
0.65%

46.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
JustsystemsEasy Postcard MaxAll versions
JustsystemsIchitaro 2021All versions
JustsystemsIchitaro 2022All versions
JustsystemsIchitaro 20231.0.1.59372
JustsystemsIchitaro Government 10All versions
JustsystemsIchitaro Government 8All versions
JustsystemsIchitaro Government 9All versions
JustsystemsIchitaro Pro 3All versions
JustsystemsIchitaro Pro 4All versions
JustsystemsIchitaro Pro 5All versions
JustsystemsJust Government 3All versions
JustsystemsJust Government 4All versions
JustsystemsJust Government 5All versions
JustsystemsJust Office 3All versions
JustsystemsJust Office 4All versions
JustsystemsJust Office 5All versions
JustsystemsJust Police 3All versions
JustsystemsJust Police 4All versions
JustsystemsJust Police 5All versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-38127?
An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause the parser to make an under-sized allocation, which can later allow for memory corruption, potentially resulting in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
How severe is CVE-2023-38127?
CVE-2023-38127 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.65% probability of exploitation in the next 30 days.
How do I fix CVE-2023-38127?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-38127?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST