CVE-2024-41139

Incorrect privilege assignment vulnerability exists in SKYSEA Client View Ver.6.010.06 to Ver.19.210.04e. If a user who can log in to the PC where the product's Windows client is installed places a specially crafted DLL file in a specific folder, arbitrary code may be executed with SYSTEM privilege.
Configurations

No configuration.

History

21 Nov 2024, 09:32

Type Values Removed Values Added
References () https://jvn.jp/en/jp/JVN84326763/ - () https://jvn.jp/en/jp/JVN84326763/ -
References () https://www.skyseaclientview.net/news/240729_02/ - () https://www.skyseaclientview.net/news/240729_02/ -

01 Aug 2024, 13:58

Type Values Removed Values Added
CWE CWE-266
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

29 Jul 2024, 14:12

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de asignación de privilegios incorrecta en SKYSEA Client View Ver.6.010.06 a Ver.19.210.04e. Si un usuario que puede iniciar sesión en el PC donde está instalado el cliente Windows del producto coloca un archivo DLL especialmente manipulado en una carpeta específica, se puede ejecutar código arbitrario con privilegios de SYSTEM.

29 Jul 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-29 09:15

Updated : 2024-11-21 09:32


NVD link : CVE-2024-41139

Mitre link : CVE-2024-41139

CVE.ORG link : CVE-2024-41139


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment