High severity8.8NVD Advisory· Published Dec 15, 2023· Updated Jun 17, 2026
CVE-2023-48387
CVE-2023-48387
Description
TAIWAN-CA(TWCA) JCICSecurityTool fails to check the source website and access locations when executing multiple Registry-related functions. In the scenario where a user is using the JCICSecurityTool and has completed identity verification, if the user browses a malicious webpage created by an attacker, the attacker can exploit this vulnerability to read or modify any registry file under HKEY_CURRENT_USER, thereby achieving remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:twca:jcicsecuritytool:4.2.3.32:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: 4.2.3.32
Patches
Vulnerability mechanics
References
1- www.twcert.org.tw/tw/cp-132-7602-a47a2-1.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.