CVE-2016-7818
Estado: ModificadaAlta (7.8)—
Untrusted search path vulnerability in Installers for Specification check program (social insurance) Ver. 9.00 and earlier, TODOKESHO print program Ver. 5.00 and earlier, Device data encryption program Ver. 1.00 and earlier, and TODOKESHO creation program Ver. 15.00 and earlier available prior to October 17, 2016 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.96%
- Percentil entre todas las CVEs puntuadas: 60
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- CWE-264
Referencias
- http://www.nenkin.go.jp/denshibenri/setsumei/0104.html
- http://www.nenkin.go.jp/denshibenri/setsumei/20140630.html
- http://www.nenkin.go.jp/denshibenri/setsumei/20150105-03.html
- http://www.nenkin.go.jp/denshibenri/setsumei/20150415.html#cmscheck
- http://www.securityfocus.com/bid/94616
- https://jvn.jp/en/jp/JVN08868688/index.html
- http://www.nenkin.go.jp/denshibenri/setsumei/0104.html
- http://www.nenkin.go.jp/denshibenri/setsumei/20140630.html
- http://www.nenkin.go.jp/denshibenri/setsumei/20150105-03.html
- http://www.nenkin.go.jp/denshibenri/setsumei/20150415.html#cmscheck
- http://www.securityfocus.com/bid/94616
- https://jvn.jp/en/jp/JVN08868688/index.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2016-7818",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "vultures@jpcert.or.jp",
"affectedData": [
{
"vendor": "Japan Pension Service",
"product": "Intstaller for Specification check program(social insurance)",
"versions": [
{
"status": "affected",
"version": "Ver. 9.00 and earlier that was available prior to October 17, 2016"
}
]
},
{
"vendor": "Japan Pension Service",
"product": "Intstaller for TODOKESHO print program",
"versions": [
{
"status": "affected",
"version": "Ver. 5.00 and earlier that was available prior to October 17, 2016"
}
]
},
{
"vendor": "Japan Pension Service",
"product": "Intstaller for Device data encryption program",
"versions": [
{
"status": "affected",
"version": "Ver. 1.00 and earlier that was available prior to October 17, 2016"
}
]
},
{
"vendor": "Japan Pension Service",
"product": "Intstaller for TODOKESHO creation program",
"versions": [
{
"status": "affected",
"version": "Ver. 15.00 and earlier that was available prior to October 17, 2016"
}
]
}
]
}
],
"published": "2017-06-09T16:29:00.797",
"references": [
{
"url": "http://www.nenkin.go.jp/denshibenri/setsumei/0104.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "http://www.nenkin.go.jp/denshibenri/setsumei/20140630.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "http://www.nenkin.go.jp/denshibenri/setsumei/20150105-03.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "http://www.nenkin.go.jp/denshibenri/setsumei/20150415.html#cmscheck",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "http://www.securityfocus.com/bid/94616",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://jvn.jp/en/jp/JVN08868688/index.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "http://www.nenkin.go.jp/denshibenri/setsumei/0104.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.nenkin.go.jp/denshibenri/setsumei/20140630.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.nenkin.go.jp/denshibenri/setsumei/20150105-03.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.nenkin.go.jp/denshibenri/setsumei/20150415.html#cmscheck",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/94616",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://jvn.jp/en/jp/JVN08868688/index.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Untrusted search path vulnerability in Installers for Specification check program (social insurance) Ver. 9.00 and earlier, TODOKESHO print program Ver. 5.00 and earlier, Device data encryption program Ver. 1.00 and earlier, and TODOKESHO creation program Ver. 15.00 and earlier available prior to October 17, 2016 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory."
},
{
"lang": "es",
"value": "Una vulnerabilidad de ruta (path) de búsqueda no segura en Instalador para programa de comprobación Specification (social insurance) versión 9.00 y anteriores, programa de impresión de TODOKESHO versión 5.00 y anteriores, programa de cifrado de datos de Device versión 1.00 y anteriores, y programa de creación de TODOKESHO versión 15.00 y anteriores disponibles antes del 17 de octubre de 2016, permite a los atacantes remotos alcanzar privilegios por medio de un archivo DLL de tipo caballo de Troya en un directorio no especificado."
}
],
"lastModified": "2026-06-17T00:53:33.173",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:japan_pension_service:device_data_encryption_program:1.00:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B2EE2251-2F1A-44FE-94E0-94C75200ED2F"
},
{
"criteria": "cpe:2.3:a:japan_pension_service:specification_check_program:9.00:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4038181E-5454-417C-AAE7-C8FD3A8EAEB0"
},
{
"criteria": "cpe:2.3:a:japan_pension_service:todokesho_creation_program:15.00:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "14C4E1CC-9E90-4E0D-823B-0B2E9EA2FE23"
},
{
"criteria": "cpe:2.3:a:japan_pension_service:todokesho_print_program:5.00:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9D55DFBC-CFE6-43C6-8A61-848FE0BCE8CB"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "vultures@jpcert.or.jp"
}