SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-10870

Memory corruption vulnerability in Rakuraku Hagaki (Rakuraku Hagaki 2018, Rakuraku Hagaki 2017, Rakuraku Hagaki 2016) and Rakuraku Hagaki Select for Ichitaro (Ichitaro 2017, Ichitaro 2016, Ichitaro 2015, Ichitaro Pro3, Ichitaro Pro2, Ichitaro Pro,…

HIGH 7.8EPSS 1.31%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.31%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Memory corruption vulnerability in Rakuraku Hagaki (Rakuraku Hagaki 2018, Rakuraku Hagaki 2017, Rakuraku Hagaki 2016) and Rakuraku Hagaki Select for Ichitaro (Ichitaro 2017, Ichitaro 2016, Ichitaro 2015, Ichitaro Pro3, Ichitaro Pro2, Ichitaro Pro, Ichitaro 2011, Ichitaro Government 8, Ichitaro Government 7, Ichitaro Government 6 and Ichitaro 2017 Trial version) allows attackers to execute arbitrary code with privileges of the application via specially crafted file.

CVSS 3.0
7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
1.31% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
justsystems/easy postcard 2016 · justsystems/easy postcard 2017 · justsystems/easy postcard 2018 · justsystems/ichitaro 2016 · justsystems/ichitaro 2017 · justsystems/ichitaro 2017 trial version · justsystems/ichitaro 2018 · justsystems/ichitaro government 6 · justsystems/ichitaro government 7 · justsystems/ichitaro government 8 · justsystems/ichitaro pro · justsystems/ichitaro pro 2 · justsystems/ichitaro pro 2011 · justsystems/ichitaro pro 3
Source
vultures@jpcert.or.jp

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.