« Volver al listado

CVE-2024-47045

Estado: AplazadaAlta (7.8)—

Privilege chaining issue exists in the installer of e-Tax software(common program). If this vulnerability is exploited, a malicious DLL prepared by an attacker may be executed with higher privileges than the application privilege.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-47045",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-47045",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-26T14:42:00.395236Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "National Tax Agency",
          "product": "The installer of e-Tax software(common program)",
          "versions": [
            {
              "status": "affected",
              "version": "All versions distributed on the NTA website before 2024 September 24"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:e-tax.nta:e-tax:*:*:*:*:*:*:*:*"
          ],
          "vendor": "e-tax.nta",
          "product": "e-tax",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "3.0.18",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-09-26T04:15:07.657",
  "references": [
    {
      "url": "https://jvn.jp/en/jp/JVN57749899/",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.e-tax.nta.go.jp/topics/2024/topics_20240924_versionup.htm",
      "source": "vultures@jpcert.or.jp"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "vultures@jpcert.or.jp",
      "description": [
        {
          "lang": "en",
          "value": "CWE-268"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Privilege chaining issue exists in the installer of e-Tax software(common program). If this vulnerability is exploited, a malicious DLL prepared by an attacker may be executed with higher privileges than the application privilege."
    },
    {
      "lang": "es",
      "value": "Existe un problema de encadenamiento de privilegios en el instalador del software e-Tax (programa común). Si se explota esta vulnerabilidad, una DLL maliciosa preparada por un atacante puede ejecutarse con privilegios superiores a los de la aplicación."
    }
  ],
  "lastModified": "2026-06-17T07:56:26.643",
  "sourceIdentifier": "vultures@jpcert.or.jp"
}