CVE-2018-0580

Severity CVSS v4.0:
Pending analysis
Type:
CWE-426 Untrusted Search Path
Publication date:
14/05/2018
Last modified:
20/06/2018

Description

Untrusted search path vulnerability in CELSYS, Inc CLIP STUDIO series (CLIP STUDIO PAINT (for Windows) EX/PRO/DEBUT Ver.1.7.3 and earlier, CLIP STUDIO ACTION (for Windows) Ver.1.5.5 and earlier, with its timestamp prior to April 25, 2018, 12:11:31, and CLIP STUDIO MODELER (for Windows) Ver.1.6.3 and earlier, with its timestamp prior to April 25, 2018, 17:02:49) allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:celsys:clip_studio_action:*:*:*:*:*:windows:*:* 1.5.5 (including)
cpe:2.3:a:celsys:clip_studio_modeler:*:*:*:*:*:windows:*:* 1.6.3 (including)
cpe:2.3:a:celsys:clip_studio_paint:*:*:*:*:*:windows:*:* 1.7.3 (including)