Cyber Resilience

CVE-2023-38127

HighPublic PoC

Published: 19 October 2023

Published
19 October 2023
Modified
04 November 2025
KEV Added
Patch
CVSS Score v3.1 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score 0.0020 41.8th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2023-38127 is a high-severity Integer Overflow or Wraparound (CWE-190) vulnerability in Justsystems Easy Postcard Max. Its CVSS base score is 7.8 (High).

Operationally, ranked at the 41.8th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability details

An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause the parser to make an under-sized allocation, which can later allow for memory corruption, potentially resulting in arbitrary code execution. An…

more

attacker can provide a malicious file to trigger this vulnerability.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

justsystems
easy postcard max
all versions
justsystems
ichitaro 2021
all versions
justsystems
ichitaro 2022
all versions
justsystems
ichitaro 2023
1.0.1.59372
justsystems
ichitaro government 10
all versions
justsystems
ichitaro government 8
all versions
justsystems
ichitaro government 9
all versions
justsystems
ichitaro pro 3
all versions
justsystems
ichitaro pro 4
all versions
justsystems
ichitaro pro 5
all versions
+9 more product configuration(s) — see NVD for full list

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References