{"api_version":"1","generated_at":"2026-07-23T10:21:07+00:00","cve":"CVE-2018-16190","urls":{"html":"https://cve.report/CVE-2018-16190","api":"https://cve.report/api/cve/CVE-2018-16190.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-16190","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-16190"},"summary":{"title":"CVE-2018-16190","description":"Untrusted search path vulnerability in UNARJ32.DLL for Win32, LHMelting for Win32, and LMLzh32.DLL (UNARJ32.DLL for Win32 Ver 1.10.1.25 and earlier, LHMelting for Win32 Ver 1.65.3.6 and earlier, LMLzh32.DLL Ver 2.67.1.2 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.","state":"PUBLIC","assigner":"vultures@jpcert.or.jp","published_at":"2019-02-13 18:29:00","updated_at":"2019-02-21 17:34:00"},"problem_types":["CWE-426"],"metrics":[],"references":[{"url":"http://jvn.jp/en/jp/JVN52168232/index.html","name":"JVN#52168232","refsource":"JVN","tags":["Third Party Advisory"],"title":"JVN#52168232: UNLHA32.DLL, UNARJ32.DLL, LHMelting and LMLzh32.DLL may insecurely load Dynamic Link Libraries","mime":"text/xml","httpstatus":"200","archivestatus":"0"},{"url":"http://micco.mars.jp/vul/2017/mhsvi20170515_02.htm","name":"http://micco.mars.jp/vul/2017/mhsvi20170515_02.htm","refsource":"MISC","tags":["Patch","Vendor Advisory"],"title":"UNLHA32.DLLにおける任意のDLL読み込みに関する脆弱性","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://micco.mars.jp/vul/2017/mhsvi20170515_03.htm","name":"https://micco.mars.jp/vul/2017/mhsvi20170515_03.htm","refsource":"MISC","tags":["Patch","Vendor Advisory"],"title":"UNARJ32.DLLにおける任意のDLL読み込みに関する脆弱性","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://micco.mars.jp/vul/2017/mhsvi20170515_05.htm","name":"http://micco.mars.jp/vul/2017/mhsvi20170515_05.htm","refsource":"MISC","tags":["Patch","Vendor Advisory"],"title":"LMLzh32.DLLにおける任意のDLL読み込みに関する脆弱性","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://micco.mars.jp/vul/2017/mhsvi20170515_04.htm","name":"http://micco.mars.jp/vul/2017/mhsvi20170515_04.htm","refsource":"MISC","tags":["Patch","Vendor Advisory"],"title":"LHMeltにおける任意のDLL読み込みに関する脆弱性","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-16190","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-16190","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"16190","vulnerable":"1","versionEndIncluding":"1.65.3.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"micco","cpe5":"lhmelting","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"16190","vulnerable":"1","versionEndIncluding":"2.67.1.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"micco","cpe5":"lmlzh32.dll","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"16190","vulnerable":"1","versionEndIncluding":"1.10.1.25","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"micco","cpe5":"unarj32.dll","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"16190","vulnerable":"1","versionEndIncluding":"2.67.1.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"micco","cpe5":"unlha32.dll","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"16190","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x86","cpe13":"*"},{"cve_year":"2018","cve_id":"16190","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"x86","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"vultures@jpcert.or.jp","ID":"CVE-2018-16190","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"UNARJ32.DLL for Win32,  LHMelting for Win32, and  LMLzh32.DLL","version":{"version_data":[{"version_value":"(UNARJ32.DLL for Win32 Ver 1.10.1.25 and earlier, LHMelting for Win32 Ver 1.65.3.6 and earlier, LMLzh32.DLL Ver 2.67.1.2 and earlier)"}]}}]},"vendor_name":"Micco"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Untrusted search path vulnerability in UNARJ32.DLL for Win32, LHMelting for Win32, and LMLzh32.DLL (UNARJ32.DLL for Win32 Ver 1.10.1.25 and earlier, LHMelting for Win32 Ver 1.65.3.6 and earlier, LMLzh32.DLL Ver 2.67.1.2 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Untrusted search path vulnerability"}]}]},"references":{"reference_data":[{"name":"JVN#52168232","refsource":"JVN","url":"http://jvn.jp/en/jp/JVN52168232/index.html"},{"name":"http://micco.mars.jp/vul/2017/mhsvi20170515_04.htm","refsource":"MISC","url":"http://micco.mars.jp/vul/2017/mhsvi20170515_04.htm"},{"name":"https://micco.mars.jp/vul/2017/mhsvi20170515_03.htm","refsource":"MISC","url":"https://micco.mars.jp/vul/2017/mhsvi20170515_03.htm"},{"name":"http://micco.mars.jp/vul/2017/mhsvi20170515_05.htm","refsource":"MISC","url":"http://micco.mars.jp/vul/2017/mhsvi20170515_05.htm"},{"name":"http://micco.mars.jp/vul/2017/mhsvi20170515_02.htm","refsource":"MISC","url":"http://micco.mars.jp/vul/2017/mhsvi20170515_02.htm"}]}},"nvd":{"publishedDate":"2019-02-13 18:29:00","lastModifiedDate":"2019-02-21 17:34:00","problem_types":["CWE-426"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:micco:lhmelting:*:*:*:*:*:*:*:*","versionEndIncluding":"1.65.3.6","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:micco:lmlzh32.dll:*:*:*:*:*:*:*:*","versionEndIncluding":"2.67.1.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:micco:unarj32.dll:*:*:*:*:*:*:*:*","versionEndIncluding":"1.10.1.25","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:micco:unlha32.dll:*:*:*:*:*:*:*:*","versionEndIncluding":"2.67.1.2","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"16190","Ordinal":"132980","Title":"CVE-2018-16190","CVE":"CVE-2018-16190","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"16190","Ordinal":"1","NoteData":"Untrusted search path vulnerability in UNARJ32.DLL for Win32, LHMelting for Win32, and LMLzh32.DLL (UNARJ32.DLL for Win32 Ver 1.10.1.25 and earlier, LHMelting for Win32 Ver 1.65.3.6 and earlier, LMLzh32.DLL Ver 2.67.1.2 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"16190","Ordinal":"2","NoteData":"2019-02-13","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"16190","Ordinal":"3","NoteData":"2019-02-13","Type":"Other","Title":"Modified"}]}}}