CVE-2018-0580
Severity CVSS v4.0:
Pending analysis
Type:
CWE-426
Untrusted Search Path
Publication date:
14/05/2018
Last modified:
20/06/2018
Description
Untrusted search path vulnerability in CELSYS, Inc CLIP STUDIO series (CLIP STUDIO PAINT (for Windows) EX/PRO/DEBUT Ver.1.7.3 and earlier, CLIP STUDIO ACTION (for Windows) Ver.1.5.5 and earlier, with its timestamp prior to April 25, 2018, 12:11:31, and CLIP STUDIO MODELER (for Windows) Ver.1.6.3 and earlier, with its timestamp prior to April 25, 2018, 17:02:49) allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:celsys:clip_studio_action:*:*:*:*:*:windows:*:* | 1.5.5 (including) | |
cpe:2.3:a:celsys:clip_studio_modeler:*:*:*:*:*:windows:*:* | 1.6.3 (including) | |
cpe:2.3:a:celsys:clip_studio_paint:*:*:*:*:*:windows:*:* | 1.7.3 (including) |
To consult the complete list of CPE names with products and versions, see this page