« Volver al listado

CVE-2017-2231

Estado: ModificadaAlta (7.8)—

Una vulnerabilidad de ruta (path) de búsqueda no confiable en el instalador de MLIT DenshiSeikabutsuSakuseiShienKensa system versión 3.02 y anteriores, distribuido hasta el 20 de junio de 2017, el archivo autoextraíble incluyendo el instalador of MLIT DenshiSeikabutsuSakuseiShienKensa system versión 3.02 y anterior, distribuido el 20 de junio de 2017, permite a un atacante alcanzar privilegios por medio de una DLL de tipo caballo Troya en un directorio no especificado.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-2231",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "Ministry of Land, Infrastructure, Transport and Tourism, Japan",
          "product": "The installer of MLIT DenshiSeikabutsuSakuseiShienKensa system",
          "versions": [
            {
              "status": "affected",
              "version": "Ver3.02 and earlier, distributed till June 20, 2017"
            }
          ]
        },
        {
          "vendor": "Ministry of Land, Infrastructure, Transport and Tourism, Japan",
          "product": "The self-extracting archive including the installer of MLIT DenshiSeikabutsuSakuseiShienKensa system",
          "versions": [
            {
              "status": "affected",
              "version": "Ver3.02 and earlier, distributed till June 20, 2017"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-07-07T13:29:01.130",
  "references": [
    {
      "url": "http://jvn.jp/en/jp/JVN06337557/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://www.mlit.go.jp/common/001189444.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://www.mlit.go.jp/gobuild/gobuild_cals_sysv3.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN06337557/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mlit.go.jp/common/001189444.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mlit.go.jp/gobuild/gobuild_cals_sysv3.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-426"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Untrusted search path vulnerability in The installer of MLIT DenshiSeikabutsuSakuseiShienKensa system Ver3.02 and earlier, distributed till June 20, 2017, The self-extracting archive including the installer of MLIT DenshiSeikabutsuSakuseiShienKensa system Ver3.02 and earlier, distributed till June 20, 2017 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de ruta (path) de búsqueda no confiable en el instalador de MLIT DenshiSeikabutsuSakuseiShienKensa system versión 3.02 y anteriores, distribuido hasta el 20 de junio de 2017, el archivo autoextraíble incluyendo el instalador of MLIT DenshiSeikabutsuSakuseiShienKensa system  versión 3.02 y anterior, distribuido el 20 de junio de 2017, permite a un atacante alcanzar privilegios por medio de una DLL de tipo caballo Troya en un directorio no especificado."
    }
  ],
  "lastModified": "2026-06-17T01:15:46.790",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mlit:denshiseikabutsusakuseishienkensa:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BAE529A4-B10F-483F-90AD-BBE0CA30DF86",
              "versionEndIncluding": "3.02"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}