CVE-2026-28267
Description
Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwritten in the system directory or backup directory by a non-administrative user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Improper file permissions in multiple i-フィルター products allow non-admin users to create/overwrite files in system/backup directories.
Vulnerability
Overview
Multiple i-フィルター products from Digital Arts Inc. are affected by an incorrect default permissions vulnerability [CWE-276]. The software installs or configures directories with file access permission settings that are too permissive, allowing a local non-administrative user to create or overwrite files in the system directory or the backup directory [1]. This issue is tracked as CVE-2026-28267.
Exploitation
Details
Exploitation requires local access to the Windows system and a non-administrative user account (privilege level PR:L). No user interaction is needed (UI:N) and the attack complexity is low (AC:L). An attacker can write arbitrary files to sensitive locations without needing to escalate privileges first [1].
Potential
Impact
The integrity impact is rated high (I:H), as the attacker can modify system files or backup data, potentially leading to persistent tampering, data corruption, or subsequent privilege escalation if the written files are executed or processed by a higher integrity process. Confidentiality and availability are not directly affected [1].
Mitigation
Status
Digital Arts has released updates to fix the permissions for the affected products, including i-フィルター 10 (Ver.10.02.00), i-フィルター 6.0 (Ver.6.00.57), and others listed in the advisory [1]. Users of any i-フィルター product (Windows version) or resold variants from OPTiM, Inventit, or Fujitsu are advised to apply the latest version. Note that this does not affect Digital Arts’ separate i-FILTER product [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: prior to Ver.4.93R13
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- biz3.optim.co.jpnvd
- jvn.jp/en/jp/JVN17307628/nvd
- sd.fjsd001.dfcenter.jp.fujitsu.com/portal/ja/kb/articles/windows%E3%81%AE%E3%83%AA%E3%83%AA%E3%83%BC%E3%82%B9%E3%83%8E%E3%83%BC%E3%83%88nvd
- www.daj.jp/shared/php/downloadset/c/parts.phpnvd
- www.daj.jp/shared/php/downloadset/c/parts.phpnvd
- www.mobi-connect.net/file/ifilter/nvd
News mentions
0No linked articles in our index yet.