Executive brief
CorvusSKK is an input method editor (IME) for Windows used to input Japanese text. A code injection vulnerability allows attackers to execute arbitrary code with user interaction, potentially compromising system security and data integrity.
Technical details
CorvusSKK contains a code injection vulnerability (CWE-94) in its Lua scripting functionality that can be exploited to achieve arbitrary code execution. The vulnerability requires local access and user interaction (local attack vector with user assistance). An attacker can craft malicious input or configuration to inject and execute arbitrary code within the context of the application. The vendor patched this issue in version 3.3.4 by disabling the vulnerable Lua features that could be leveraged for attacks.
Affected products
- SASAKI Nobuyuki CorvusSKK prior to 3.3.4
Timeline
- 2026-08-26: disclosed
- 2026-08-14: patched: Version 3.3.4 released with CVE-2026-76148 fix