An unquoted search path vulnerability exists in JustSystems JUST Online Update for J-License bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of the Windows service if it is placed in a certain path. Affected products are bundled with the following product series: Office and Office Integrated Software, ATOK, Hanako, JUST PDF, Shuriken, Homepage Builder, JUST School, JUST Smile Class, JUST Smile, JUST Frontier, JUST Jump, and Tri-De DetaProtect.
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Atok_medical_2 | Justsystems | * | * |
| Atok_medical_3 | Justsystems | * | * |
| Atok_pro_3 | Justsystems | * | * |
| Atok_pro_4 | Justsystems | * | * |
| Atok_pro_5 | Justsystems | * | * |
| Hanako_police_5 | Justsystems | * | * |
| Hanako_police_6 | Justsystems | * | * |
| Hanako_police_7 | Justsystems | * | * |
| Hanako_pro_3 | Justsystems | * | * |
| Hanako_pro_4 | Justsystems | * | * |
| Hanako_pro_5 | Justsystems | * | * |
| Homepage_builder_20 | Justsystems | * | * |
| Homepage_builder_21 | Justsystems | * | * |
| Homepage_builder_22 | Justsystems | * | * |
| Ichitaro_government_10 | Justsystems | * | * |
| Ichitaro_government_8 | Justsystems | - (including) | - (including) |
| Ichitaro_government_9 | Justsystems | * | * |
| Ichitaro_pro_3 | Justsystems | * | * |
| Ichitaro_pro_4 | Justsystems | * | * |
| Ichitaro_pro_5 | Justsystems | * | * |
| Just_calc_3 | Justsystems | * | * |
| Just_calc_4 | Justsystems | * | * |
| Just_calc_5 | Justsystems | * | * |
| Just_focus_3 | Justsystems | * | * |
| Just_focus_4 | Justsystems | * | * |
| Just_frontier_3 | Justsystems | * | * |
| Just_government_2 | Justsystems | * | * |
| Just_government_3 | Justsystems | * | * |
| Just_government_4 | Justsystems | * | * |
| Just_government_5 | Justsystems | * | * |
| Just_jump_8 | Justsystems | * | * |
| Just_jump_class | Justsystems | * | * |
| Just_jump_class_2 | Justsystems | * | * |
| Just_medical_2 | Justsystems | * | * |
| Just_medical_3 | Justsystems | * | * |
| Just_medical_4 | Justsystems | * | * |
| Just_medical_5 | Justsystems | * | * |
| Just_note_3 | Justsystems | * | * |
| Just_note_4 | Justsystems | * | * |
| Just_note_5 | Justsystems | * | * |
| Just_office_2 | Justsystems | * | * |
| Just_office_3 | Justsystems | * | * |
| Just_office_4 | Justsystems | * | * |
| Just_office_5 | Justsystems | * | * |
| Just_pdf_3 | Justsystems | * | * |
| Just_pdf_4 | Justsystems | * | * |
| Just_pdf_5 | Justsystems | * | * |
| Just_police_2 | Justsystems | * | * |
| Just_police_3 | Justsystems | * | * |
| Just_police_4 | Justsystems | * | * |
| Just_police_5 | Justsystems | * | * |
| Just_school_6 | Justsystems | * | * |
| Just_school_7 | Justsystems | * | * |
| Just_smile_6 | Justsystems | * | * |
| Just_smile_7 | Justsystems | * | * |
| Just_smile_8 | Justsystems | * | * |
| Just_smile_class_2 | Justsystems | * | * |
| Shuriken_pro_6 | Justsystems | * | * |
| Shuriken_pro_7 | Justsystems | * | * |
| Tri-de_dataprotect | Justsystems | * | * |