Vulnerability Details CVE-2023-38128
An out-of-bounds write vulnerability exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause a type confusion, which can lead to memory corruption and eventually arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.3%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2023-38128
-
cpe:2.3:a:justsystems:easy_postcard_max:-
-
cpe:2.3:a:justsystems:ichitaro_2021:-
-
cpe:2.3:a:justsystems:ichitaro_2022:-
-
cpe:2.3:a:justsystems:ichitaro_2023:1.0.1.59372
-
cpe:2.3:a:justsystems:ichitaro_government_10:-
-
cpe:2.3:a:justsystems:ichitaro_government_8:-
-
cpe:2.3:a:justsystems:ichitaro_government_9:-
-
cpe:2.3:a:justsystems:ichitaro_pro_3:-
-
cpe:2.3:a:justsystems:ichitaro_pro_4:-
-
cpe:2.3:a:justsystems:ichitaro_pro_5:-
-
cpe:2.3:a:justsystems:just_government_3:-
-
cpe:2.3:a:justsystems:just_government_4:-
-
cpe:2.3:a:justsystems:just_government_5:-
-
cpe:2.3:a:justsystems:just_office_3:-
-
cpe:2.3:a:justsystems:just_office_4:-
-
cpe:2.3:a:justsystems:just_office_5:-
-
cpe:2.3:a:justsystems:just_police_3:-
-
cpe:2.3:a:justsystems:just_police_4:-
-
cpe:2.3:a:justsystems:just_police_5:-