Vulnerability Description
Incorrect privilege assignment vulnerability exists in SKYSEA Client View Ver.6.010.06 to Ver.19.210.04e. If a user who can log in to the PC where the product's Windows client is installed places a specially crafted DLL file in a specific folder, arbitrary code may be executed with SYSTEM privilege.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Skygroup | Skysea Client View | >= 6.010.06, < 19.300.09h |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/jp/JVN84326763/Third Party Advisory
- https://www.skyseaclientview.net/news/240729_02/Vendor Advisory
- https://jvn.jp/en/jp/JVN84326763/Third Party Advisory
- https://www.skyseaclientview.net/news/240729_02/Vendor Advisory
FAQ
What is CVE-2024-41139?
CVE-2024-41139 is a vulnerability with a CVSS score of 7.8 (HIGH). Incorrect privilege assignment vulnerability exists in SKYSEA Client View Ver.6.010.06 to Ver.19.210.04e. If a user who can log in to the PC where the product's Windows client is installed places a sp...
How severe is CVE-2024-41139?
CVE-2024-41139 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-41139?
Check the references section above for vendor advisories and patch information. Affected products include: Skygroup Skysea Client View.