« Volver al listado

CVE-2017-2214

Estado: ModificadaAlta (8.4)—

Untrusted search path vulnerability in AppCheck and AppCheck Pro prior to version 2.0.1.15 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-2214",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 8.4,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.5
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "JIRANSOFT JAPAN, INC.",
          "product": "AppCheck",
          "versions": [
            {
              "status": "affected",
              "version": "prior to Version 2.0.1.15"
            }
          ]
        },
        {
          "vendor": "JIRANSOFT JAPAN, INC.",
          "product": "AppCheck Pro",
          "versions": [
            {
              "status": "affected",
              "version": "prior to Version 2.0.1.15"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-06-09T16:29:02.047",
  "references": [
    {
      "url": "http://jvn.jp/en/jp/JVN99737748/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN99737748/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-426"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Untrusted search path vulnerability in AppCheck and AppCheck Pro prior to version 2.0.1.15 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de ruta (path) de búsqueda no segura en AppCheck y AppCheck Pro anterior a versión 2.0.1.15, permite a un atacante ejecutar código arbitrario por medio de un archivo ejecutable especialmente diseñado en un directorio no especificado."
    }
  ],
  "lastModified": "2026-06-17T01:15:44.793",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:jiransoft:appcheck:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "840F0D93-38C2-4E4F-A206-FFF6FC703BD2",
              "versionEndIncluding": "2.0.1.14"
            },
            {
              "criteria": "cpe:2.3:a:jiransoft:appcheck_pro:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E6D6B8B-F74C-4B2A-9552-8FF4534FD4F6",
              "versionEndIncluding": "2.0.1.14"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}