CVE-2021-20722: High severity fujitsu scansnap manager vulnerability
Untrusted search path vulnerability in the installers of ScanSnap Manager prior to versions V7.0L20 and the Software Download Installer prior to WinSSInst2JP.exe and WinSSInst2iX1500JP.exe allows an attacker to gain privileges and execute arbitrary code with the privilege of the user invoking the installer via a Trojan horse DLL in an unspecified directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20722?
The severity of CVE-2021-20722 is high with a CVSS score of 7.8.
How does CVE-2021-20722 affect Fujitsu ScanSnap Manager?
CVE-2021-20722 affects Fujitsu ScanSnap Manager prior to version 7.0L20.
What is the impact of CVE-2021-20722?
CVE-2021-20722 allows an attacker to gain privileges and execute arbitrary code with the privilege of the user invoking the installer.
How can I fix CVE-2021-20722 in ScanSnap Manager?
To fix CVE-2021-20722, you should update ScanSnap Manager to version 7.0L20 or later.
Where can I find more information about CVE-2021-20722?
You can find more information about CVE-2021-20722 at the following references: [CVE-2021-20722](https://jvn.jp/en/jp/JVN65733194/index.html) and [Fujitsu ScanSnap website](https://scansnap.fujitsu.com/global/dl/).