CVE-2023-22336: Dos-Osaka Rakuraku Pc Cloud Agent

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to upload a specially crafted file to an arbitrary directory. As a result of exploiting this vulnerability with CVE-2023-22335 and CVE-2023-22344 vulnerabilities together, it may allow a remote attacker to execute an arbitrary code with SYSTEM privileges by sending a specially crafted script to the affected device.

Affected products

  • Dos-Osaka Rakuraku Pc Cloud Agent: up to and including 2.1.8
  • Dos-Osaka SS1: up to and including 13.0.0.40

Published 2023-03-06. Last modified 2026-06-17.