CVE-2022-36344

An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of the Windows service if it is placed in a certain path. Affected products are bundled with the following product series: Office and Office Integrated Software, ATOK, Hanako, JUST PDF, Shuriken, Homepage Builder, JUST School, JUST Smile Class, JUST Smile, JUST Frontier, JUST Jump, and Tri-De DetaProtect.

Published: 2022-08-16 Last update: 2024-11-21 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2022-36344 is rated Moderate Risk (64.3/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.71%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2022-36344

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-08-18 0.63% 0.71% +0.08%
2 2025-08-17 0.27% 0.63% +0.35%
3 2025-05-11 0.27%

Full EPSS history (10 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2022-36344

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
9.8 3.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 5.9 [email protected]

Weakness enumeration for CVE-2022-36344

Affected software / configurations for CVE-2022-36344

Vendor Product Version Raw CPE
justsystems atok_medical_2 cpe:2.3:a:justsystems:atok_medical_2:*:*:*:*:*:windows:*:*
justsystems atok_medical_3 cpe:2.3:a:justsystems:atok_medical_3:*:*:*:*:*:windows:*:*
justsystems atok_pro_3 cpe:2.3:a:justsystems:atok_pro_3:*:*:*:*:*:windows:*:*
justsystems atok_pro_4 cpe:2.3:a:justsystems:atok_pro_4:*:*:*:*:*:windows:*:*
justsystems atok_pro_5 cpe:2.3:a:justsystems:atok_pro_5:*:*:*:*:*:windows:*:*
justsystems hanako_police_5 cpe:2.3:a:justsystems:hanako_police_5:*:*:*:*:*:*:*:*
justsystems hanako_police_6 cpe:2.3:a:justsystems:hanako_police_6:*:*:*:*:*:*:*:*
justsystems hanako_police_7 cpe:2.3:a:justsystems:hanako_police_7:*:*:*:*:*:*:*:*
justsystems hanako_pro_3 cpe:2.3:a:justsystems:hanako_pro_3:*:*:*:*:*:*:*:*
justsystems hanako_pro_4 cpe:2.3:a:justsystems:hanako_pro_4:*:*:*:*:*:*:*:*
justsystems hanako_pro_5 cpe:2.3:a:justsystems:hanako_pro_5:*:*:*:*:*:*:*:*
justsystems homepage_builder_20 cpe:2.3:a:justsystems:homepage_builder_20:*:*:*:*:*:*:*:*
justsystems homepage_builder_21 cpe:2.3:a:justsystems:homepage_builder_21:*:*:*:*:*:*:*:*
justsystems homepage_builder_22 cpe:2.3:a:justsystems:homepage_builder_22:*:*:*:*:*:*:*:*
justsystems ichitaro_government_10 cpe:2.3:a:justsystems:ichitaro_government_10:*:*:*:*:*:*:*:*
justsystems ichitaro_government_8 cpe:2.3:a:justsystems:ichitaro_government_8:-:*:*:*:*:*:*:*
justsystems ichitaro_government_9 cpe:2.3:a:justsystems:ichitaro_government_9:*:*:*:*:*:*:*:*
justsystems ichitaro_pro_3 cpe:2.3:a:justsystems:ichitaro_pro_3:*:*:*:*:*:*:*:*
justsystems ichitaro_pro_4 cpe:2.3:a:justsystems:ichitaro_pro_4:*:*:*:*:*:*:*:*
justsystems ichitaro_pro_5 cpe:2.3:a:justsystems:ichitaro_pro_5:*:*:*:*:*:*:*:*
justsystems just_calc_3 cpe:2.3:a:justsystems:just_calc_3:*:*:*:*:*:*:*:*
justsystems just_calc_4 cpe:2.3:a:justsystems:just_calc_4:*:*:*:*:*:*:*:*
justsystems just_calc_5 cpe:2.3:a:justsystems:just_calc_5:*:*:*:*:*:*:*:*
justsystems just_focus_3 cpe:2.3:a:justsystems:just_focus_3:*:*:*:*:*:*:*:*
justsystems just_focus_4 cpe:2.3:a:justsystems:just_focus_4:*:*:*:*:*:*:*:*
justsystems just_frontier_3 cpe:2.3:a:justsystems:just_frontier_3:*:*:*:*:*:*:*:*
justsystems just_government_2 cpe:2.3:a:justsystems:just_government_2:*:*:*:*:*:*:*:*
justsystems just_government_3 cpe:2.3:a:justsystems:just_government_3:*:*:*:*:*:*:*:*
justsystems just_government_4 cpe:2.3:a:justsystems:just_government_4:*:*:*:*:*:*:*:*
justsystems just_government_5 cpe:2.3:a:justsystems:just_government_5:*:*:*:*:*:*:*:*
justsystems just_jump_8 cpe:2.3:a:justsystems:just_jump_8:*:*:*:*:*:*:*:*
justsystems just_jump_class cpe:2.3:a:justsystems:just_jump_class:*:*:*:*:*:*:*:*
justsystems just_jump_class_2 cpe:2.3:a:justsystems:just_jump_class_2:*:*:*:*:*:*:*:*
justsystems just_medical_2 cpe:2.3:a:justsystems:just_medical_2:*:*:*:*:*:*:*:*
justsystems just_medical_3 cpe:2.3:a:justsystems:just_medical_3:*:*:*:*:*:*:*:*
justsystems just_medical_4 cpe:2.3:a:justsystems:just_medical_4:*:*:*:*:*:*:*:*
justsystems just_medical_5 cpe:2.3:a:justsystems:just_medical_5:*:*:*:*:*:*:*:*
justsystems just_note_3 cpe:2.3:a:justsystems:just_note_3:*:*:*:*:*:*:*:*
justsystems just_note_4 cpe:2.3:a:justsystems:just_note_4:*:*:*:*:*:*:*:*
justsystems just_note_5 cpe:2.3:a:justsystems:just_note_5:*:*:*:*:*:*:*:*
justsystems just_office_2 cpe:2.3:a:justsystems:just_office_2:*:*:*:*:*:*:*:*
justsystems just_office_3 cpe:2.3:a:justsystems:just_office_3:*:*:*:*:*:*:*:*
justsystems just_office_4 cpe:2.3:a:justsystems:just_office_4:*:*:*:*:*:*:*:*
justsystems just_office_5 cpe:2.3:a:justsystems:just_office_5:*:*:*:*:*:*:*:*
justsystems just_pdf_3 cpe:2.3:a:justsystems:just_pdf_3:*:*:*:*:*:*:*:*
justsystems just_pdf_4 cpe:2.3:a:justsystems:just_pdf_4:*:*:*:*:*:*:*:*
justsystems just_pdf_5 cpe:2.3:a:justsystems:just_pdf_5:*:*:*:*:*:*:*:*
justsystems just_pdf_5 cpe:2.3:a:justsystems:just_pdf_5:*:*:*:*:pro:*:*:*
justsystems just_police_2 cpe:2.3:a:justsystems:just_police_2:*:*:*:*:*:*:*:*
justsystems just_police_3 cpe:2.3:a:justsystems:just_police_3:*:*:*:*:*:*:*:*
justsystems just_police_4 cpe:2.3:a:justsystems:just_police_4:*:*:*:*:*:*:*:*
justsystems just_police_5 cpe:2.3:a:justsystems:just_police_5:*:*:*:*:*:*:*:*
justsystems just_school_6 cpe:2.3:a:justsystems:just_school_6:*:*:*:*:*:*:*:*
justsystems just_school_7 cpe:2.3:a:justsystems:just_school_7:*:*:*:*:*:*:*:*
justsystems just_smile_6 cpe:2.3:a:justsystems:just_smile_6:*:*:*:*:*:*:*:*
justsystems just_smile_7 cpe:2.3:a:justsystems:just_smile_7:*:*:*:*:*:*:*:*
justsystems just_smile_8 cpe:2.3:a:justsystems:just_smile_8:*:*:*:*:*:*:*:*
justsystems just_smile_class_2 cpe:2.3:a:justsystems:just_smile_class_2:*:*:*:*:*:*:*:*
justsystems shuriken_pro_6 cpe:2.3:a:justsystems:shuriken_pro_6:*:*:*:*:*:*:*:*
justsystems shuriken_pro_7 cpe:2.3:a:justsystems:shuriken_pro_7:*:*:*:*:*:*:*:*
justsystems tri-de_dataprotect cpe:2.3:a:justsystems:tri-de_dataprotect:*:*:*:*:*:*:*:*

References for CVE-2022-36344

cvelogic Threat Intelligence