Lucene search

K
cveJpcertCVE-2024-21805
HistoryMar 12, 2024 - 8:15 a.m.

CVE-2024-21805

2024-03-1208:15:45
CWE-284
jpcert
web.nvd.nist.gov
40
cve-2024-21805
skysea client view
vulnerability
access control
arbitrary file
dll
exploit
nvd

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.1

Confidence

High

EPSS

0

Percentile

9.0%

Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary file may be placed in the specific folder by a user who can log in to the PC where the product’s Windows client is installed. In case the file is a specially crafted DLL file, arbitrary code may be executed with SYSTEM privilege.

Affected configurations

Vulners
Vulnrichment
Node
sky_co.\,ltd.skysea_client_viewRange16.10019.2
VendorProductVersionCPE
sky_co.\,ltd.skysea_client_view*cpe:2.3:a:sky_co.\,ltd.:skysea_client_view:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Sky Co.,LTD.",
    "product": "SKYSEA Client View",
    "versions": [
      {
        "version": "versions from Ver.16.100 prior to Ver.19.2",
        "status": "affected"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.1

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVE-2024-21805