CVE-2026-23703
Received
Received - Intake
Incorrect Default Permissions in FinalCode Installer Enables SYSTEM Code Execution
Publication date: 2026-02-26
Last updated on: 2026-02-26
Assigner: JPCERT/CC
Description
Description
The installer of FinalCode Client provided by Digital Arts Inc. contains an incorrect default permissions vulnerability. A non-administrative user may execute arbitrary code with SYSTEM privilege.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| digital_arts_inc | finalcode_client | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |