🛡️ CVE-2022-36344
🔴 CVSS 9.8 — Critical ✅ No Known Exploit CWE-428 NVD
9.8
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of the Windows service if it is placed in a certain path. Affected products are bundled with the following product series: Office and Office Integrated Software, ATOK, Hanako, JUST PDF, Shuriken, Homepage Builder, JUST School, JUST Smile Class, JUST Smile, JUST Frontier, JUST Jump, and Tri-De DetaProtect.

Details

Severity CRITICAL
CVSS Score 9.8
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE CWE-428
Public Exploit ✅ No
Source NVD
Published 2022-08-16
Updated 2026-06-08
Modified 2024-11-21
Fix URL N/A

Affected Packages

Software From version Fixed in
atok-medical-2
atok-medical-3
atok-pro-3
atok-pro-4
atok-pro-5
hanako-police-5
hanako-police-6
hanako-police-7
hanako-pro-3
hanako-pro-4
hanako-pro-5
homepage-builder-20
homepage-builder-21
homepage-builder-22
ichitaro-government-10
ichitaro-government-8
ichitaro-government-9
ichitaro-pro-3
ichitaro-pro-4
ichitaro-pro-5
just-calc-3
just-calc-4
just-calc-5
just-focus-3
just-focus-4
just-frontier-3
just-government-2
just-government-3
just-government-4
just-government-5
just-jump-8
just-jump-class
just-jump-class-2
just-medical-2
just-medical-3
just-medical-4
just-medical-5
just-note-3
just-note-4
just-note-5
just-office-2
just-office-3
just-office-4
just-office-5
just-pdf-3
just-pdf-4
just-pdf-5
just-police-2
just-police-3
just-police-4
just-police-5
just-school-6
just-school-7
just-smile-6
just-smile-7
just-smile-8
just-smile-class-2
shuriken-pro-6
shuriken-pro-7
tri-de-dataprotect

Patch Gap Protection

Running software with known vulnerabilities?

BotEraser can help reduce exposure by blocking IPs associated with exploit activity — even before a patch is available.

Start Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.