First published: Mon May 24 2021(Updated: )
Untrusted search path vulnerability in the installers of ScanSnap Manager prior to versions V7.0L20 and the Software Download Installer prior to WinSSInst2JP.exe and WinSSInst2iX1500JP.exe allows an attacker to gain privileges and execute arbitrary code with the privilege of the user invoking the installer via a Trojan horse DLL in an unspecified directory.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Fujitsu Scansnap Manager | <7.0l20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-20722 is high with a CVSS score of 7.8.
CVE-2021-20722 affects Fujitsu ScanSnap Manager prior to version 7.0L20.
CVE-2021-20722 allows an attacker to gain privileges and execute arbitrary code with the privilege of the user invoking the installer.
To fix CVE-2021-20722, you should update ScanSnap Manager to version 7.0L20 or later.
You can find more information about CVE-2021-20722 at the following references: [CVE-2021-20722](https://jvn.jp/en/jp/JVN65733194/index.html) and [Fujitsu ScanSnap website](https://scansnap.fujitsu.com/global/dl/).