TDSCSA00038: Installers of development tool software products for Toshiba original core-based microcontrollers have a security vulnerability

April 2, 2021
Toshiba Electronic Devices & Storage Corporation

Toshiba Electronic Devices & Storage Corporation ("Toshiba") wishes to inform the users that a security vulnerability has been found in the installers of the development tool software products for Toshiba original core-based microcontrollers. If your Windows PC contains unauthorized DLL maliciously implanted by an attacker and you execute the affected installers of the software, the affected installers may cause insecure operation of your Windows PC.
The affected products (“Products”) of the development tool software products for Toshiba original core-based microcontrollers and their versions are shown in "List of affected products". If you use the Products, please refer to “Contact and way to get the updated products” in order to get updates from our department in charge. The EOL announced products listed below also have a security vulnerability but no updated files, so please avoid use of these products.

List of affected products
Contact and way to get the updated products
EOL announced products

All products of microcontroller development tool software for Toshiba original core-based microcontrollers released before August 2019. 

List of affected products

  • Toshiba Integrated Development Environment, or Flash programmer
    Select “Help” – “Version” in the main menu, and the model name or product name and the version number are displayed.
  • Debugger
    Select “Help” – “About TMPRO Debugger” in the main menu, and the version number is displayed.
  • Compiler (C compiler, C compiler & assembler set, etc.)
    “Name” and “Version” can be confirmed by “Control Panel” – “Programs and Features”. 

The affected installers of the Products contain an issue with their DLL (Dynamic Link Libraries) path, which may unintentionally load DLL if executed.

If your Windows PC contains unauthorized DLL maliciously implanted by an attacker and you execute the affected installers of the Products, the affected installers may cause unintentionally operations on your Windows PC.

Please use the updated products.
The updated products should be used on Windows 10.

Information about the vulnerability is as follows.

Please contact our website and get the updated products from our department in charge. 
Please enter the necessary information in "Contact us" at the top of the our website and get the updated products from the department in charge. 
Please fill in the required form "*" and enter "Update microcontroller development tool software" and your "Updated Products" in " Inquiry Details ".