CVE-2023-22282

CVSS V2 None CVSS V3 None
Description
WAB-MAT Ver.5.0.0.8 and earlier starts another program with an unquoted file path. Since a registered Windows service path contains spaces and are unquoted, if a malicious executable is placed on a certain path, the executable may be executed with the privilege of the Windows service.
Overview
  • CVE ID
  • CVE-2023-22282
  • Assigner
  • vultures@jpcert.or.jp
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-04-11T09:15:07
  • Last Modified Date
  • 2023-04-18T14:04:11
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:a:elecom:wab-mat:*:*:*:*:*:*:*:* 1 OR 5.0.2.2
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* 0 OR
History
Created Old Value New Value Data Type Notes
2023-04-17 04:29:02 Added to TrackCVE
2023-04-17 12:00:46 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-04-18 15:00:18 2023-04-18T14:04:11 CVE Modified Date updated
2023-04-18 15:00:18 Undergoing Analysis Analyzed Vulnerability Status updated
2023-04-18 15:00:19 Weakness Enumeration new
2023-04-18 15:00:22 CPE Information updated