CVE-2023-22660
A heap-based buffer overflow vulnerability exists in the way Ichitaro version 2022 1.0.1.57600 processes certain LayoutBox stream record types.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A heap-based buffer overflow vulnerability exists in the way Ichitaro version 2022 1.0.1.57600 processes certain LayoutBox stream record types. A specially crafted document can cause a buffer overflow, leading to memory corruption, which can result in arbitrary code execution.To trigger this vulnerability, the victim would need to open a malicious, attacker-created document.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.54% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-122
- Affected
- justsystems/ichitaro 2022
- Source
- talos-cna@cisco.com
References
- https://jvn.jp/en/jp/JVN79149117/Third Party Advisory, VDB Entry
- https://talosintelligence.com/vulnerability_reports/TALOS-2023-1722Exploit, Third Party Advisory
- https://jvn.jp/en/jp/JVN79149117/Third Party Advisory, VDB Entry
- https://talosintelligence.com/vulnerability_reports/TALOS-2023-1722Exploit, Third Party Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1722
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.