Published:2026/08/05  Last Updated:2026/08/05

JVN#28045338
Multiple vulnerabilities in NetKids iMark

Overview

NetKids iMark provided by Integrated Systems Technologies, Inc. contains multiple vulnerabilities.

Products Affected

  • NetKids iMark versions V5.2.5.0 and earlier

Description

NetKids iMark provided by Integrated Systems Technologies, Inc. contains multiple vulnerabilities listed below:

  • Uncontrolled search path element (CWE-427)
    • CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 5.4
    • CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Base Score 6.7
    • CVE-2026-66344
  • Unquoted search path or element (CWE-428)
    • CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.4
    • CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Base Score 6.7
    • CVE-2026-66839

Impact

  • Arbitrary code may be executed with SYSTEM privilege by an attacker who logged in to the affected device (CVE-2026-66344).
  • Arbitrary code may be executed with SYSTEM privilege by an attacker with write access to the system folder (CVE-2026-66839).

Solution

Apply the Workaround
The developer plans to provide an update addressing these vulnerabilities.
Until the update is available, apply the workaround based on the information provided by the developer.

References

  1. Japan Vulnerability Notes JVNTA#91240916
    Insecure DLL Loading and Command Execution Issues on Many Windows Application Programs

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-66344
CVE-2026-66839
JVN iPedia JVNDB-2026-000108