Vulnerability CVE-2009-4738


Published: 2013-01-18   Modified: 2013-01-19

Description:
Unspecified vulnerability in JustSystems Corporation ATOK 2006 through 2009 and ATOK flat-rate service, and Just Smile 4 with the ATOK Smile module, allows physically proximate users to bypass the screen lock and execute commands with system privileges via unknown vectors related to "launching external applications."

Type:

CWE-noinfo

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.2/10
10/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Justsystems -> ATOK 
Justsystems -> Atok flat-rate service 
Justsystems -> Just smile 

 References:
http://www.justsystems.com/jp/info/js09003.html
http://www.securityfocus.com/bid/36220
http://secunia.com/advisories/36560
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000057.html
http://jvn.jp/en/jp/JVN57040664/index.html

Copyright 2024, cxsecurity.com

 

Back to Top