Published:2026/08/05 Last Updated:2026/08/05
JVN#28045338
Multiple vulnerabilities in NetKids iMark
Overview
NetKids iMark provided by Integrated Systems Technologies, Inc. contains multiple vulnerabilities.
Products Affected
- NetKids iMark versions V5.2.5.0 and earlier
Description
NetKids iMark provided by Integrated Systems Technologies, Inc. contains multiple vulnerabilities listed below:
- Uncontrolled search path element (CWE-427)
- CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 5.4
- CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Base Score 6.7
- CVE-2026-66344
- Unquoted search path or element (CWE-428)
- CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.4
- CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Base Score 6.7
- CVE-2026-66839
Impact
- Arbitrary code may be executed with
SYSTEMprivilege by an attacker who logged in to the affected device (CVE-2026-66344). - Arbitrary code may be executed with
SYSTEMprivilege by an attacker with write access to the system folder (CVE-2026-66839).
Solution
Apply the Workaround
The developer plans to provide an update addressing these vulnerabilities.
Until the update is available, apply the workaround based on the information provided by the developer.
Vendor Status
References
-
Japan Vulnerability Notes JVNTA#91240916
Insecure DLL Loading and Command Execution Issues on Many Windows Application Programs
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-66344 |
|
CVE-2026-66839 |
|
| JVN iPedia |
JVNDB-2026-000108 |