PT-2024-19066 · Unknown · Skysea Client View
Ken Kitahara
·
Published
2024-03-12
·
Updated
2025-05-23
·
CVE-2024-21805
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2
Description
An improper access control vulnerability exists in a specific folder of the software. This vulnerability can be exploited by a user who can log in to the PC where the product's Windows client is installed, allowing them to place an arbitrary file in the specific folder. If the file is a specially crafted DLL file, arbitrary code may be executed with SYSTEM privilege.
Recommendations
For SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2, update to version Ver.19.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the specific folder to minimize the risk of exploitation.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Skysea Client View