# CVE-2023-48387

## Summary

- **CVE ID:** CVE-2023-48387
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- **CWE:** CWE-940
- **Published:** Dec 15, 2023
- **Last Modified:** Mar 13, 2026

## Description

TAIWAN-CA(TWCA) JCICSecurityTool  fails to check the source website and access locations when executing multiple Registry-related functions. In the scenario where a user is using the JCICSecurityTool and has completed identity verification, if the user browses a malicious webpage created by an attacker, the attacker can exploit this vulnerability to read or modify any registry file under HKEY_CURRENT_USER, thereby achieving remote code execution.

## Affected Products

- TAIWAN-CA(TWCA) — JCICSecurityTool (4.2.3.32)

## References

- [CNA](https://www.twcert.org.tw/tw/cp-132-7602-a47a2-1.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.02%
- **EPSS Percentile:** 76.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._