CVE-2009-4738
Unspecified vulnerability in JustSystems Corporation ATOK 2006 through 2009 and ATOK flat-rate service, and Just Smile 4 with the ATOK Smile module, allows physically proximate users to bypass the screen lock and execute commands with system privileges…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.39%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in JustSystems Corporation ATOK 2006 through 2009 and ATOK flat-rate service, and Just Smile 4 with the ATOK Smile module, allows physically proximate users to bypass the screen lock and execute commands with system privileges via unknown vectors related to "launching external applications."
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.39% probability · 33th percentile
- CISA KEV
- Not listed
- Affected
- justsystems/atok · justsystems/atok flat-rate service · justsystems/just smile
- Source
- cve@mitre.org
References
- http://jvn.jp/en/jp/JVN57040664/index.html
- http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000057.html
- http://secunia.com/advisories/36560Vendor Advisory
- http://www.justsystems.com/jp/info/js09003.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/36220
- http://jvn.jp/en/jp/JVN57040664/index.html
- http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000057.html
- http://secunia.com/advisories/36560Vendor Advisory
- http://www.justsystems.com/jp/info/js09003.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/36220
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.