Executive brief
Multiple Digital Arts i-フィルター web filtering products for Windows contain a security flaw where file permissions are not correctly restricted. This software is used to filter web content and manage browsing safety on corporate and personal computers. An unauthorized user with local access to a computer could exploit this to create or overwrite critical system or backup files, potentially compromising the integrity of the operating system or the filtering software itself.
Technical details
The vulnerability is classified as Incorrect Default Permissions (CWE-276) within the Windows versions of several Digital Arts web filtering products and their OEM variants (OPTiM, Inventit, Fujitsu). The root cause is improper file access permission settings in the system or backup directories used by the application. A local attacker with low-level privileges can exploit this to create new files or overwrite existing ones in protected directories. This could lead to unauthorized modification of system data or application configuration. Patches have been released for all affected product lines, and users are advised to update to the latest versions (e.g., i-フィルター 10 Ver.10.02.00 or i-FILTER MultiAgent Ver.4.93R13).
Affected products
- Digital Arts Inc. i-フィルター 10 (Windows) Prior to 10.02.00
- Digital Arts Inc. i-フィルター 6.0 Prior to 6.00.57
- Digital Arts Inc. i-フィルター for ネットカフェ Prior to 6.10.57
- Digital Arts Inc. i-フィルター for マルチデバイス (Windows) Prior to 6.00.57
- Digital Arts Inc. i-フィルター for ZAQ (Windows) Prior to 6.00.57
- Digital Arts Inc. i-フィルター for プロバイダー Prior to 2.00.30
- Digital Arts Inc. i-FILTER ブラウザー&クラウド MultiAgent for Windows Prior to 4.93R13
- Digital Arts Inc. DigitalArts@Cloud Agent (Windows) Prior to 1.70R01
- OPTiM Corporation Optimal Biz Web Filtering Powered by i-FILTER (Windows) Prior to 4.93R13
- Inventit Inc. MobiConnect i-FILTER Browser Option MultiAgent for Windows Prior to 4.93R13
- Fujitsu Limited i-FILTER Browser & Cloud MultiAgent for Windows Prior to 4.93R13
Timeline
- 2026-03-09: advisory: Initial advisory published by JVN
- 2026-03-10: disclosed: CVE published to NVD
- 2026-04-03: other: Advisory updated to fix typos in description
References
- https://biz3.optim.co.jp/
- https://jvn.jp/en/jp/JVN17307628/
- https://sd.fjsd001.dfcenter.jp.fujitsu.com/portal/ja/kb/articles/windows%E3%81%AE%E3%83%AA%E3%83%AA%E3%83%BC%E3%82%B9%E3%83%8E%E3%83%BC%E3%83%88
- https://www.daj.jp/shared/php/downloadset/c/parts.php?page=dl&filename=information_20260309_01.pdf
- https://www.daj.jp/shared/php/downloadset/c/parts.php?page=dl&filename=information_20260309_02.pdf
- https://www.mobi-connect.net/file/ifilter/