2024-12-08 03:06:42 +00:00

72 lines
2.4 KiB
JSON

{
"id": "CVE-2024-41139",
"sourceIdentifier": "vultures@jpcert.or.jp",
"published": "2024-07-29T09:15:02.563",
"lastModified": "2024-11-21T09:32:18.463",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Incorrect privilege assignment vulnerability exists in SKYSEA Client View Ver.6.010.06 to Ver.19.210.04e. If a user who can log in to the PC where the product's Windows client is installed places a specially crafted DLL file in a specific folder, arbitrary code may be executed with SYSTEM privilege."
},
{
"lang": "es",
"value": "Existe una vulnerabilidad de asignaci\u00f3n de privilegios incorrecta en SKYSEA Client View Ver.6.010.06 a Ver.19.210.04e. Si un usuario que puede iniciar sesi\u00f3n en el PC donde est\u00e1 instalado el cliente Windows del producto coloca un archivo DLL especialmente manipulado en una carpeta espec\u00edfica, se puede ejecutar c\u00f3digo arbitrario con privilegios de SYSTEM."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-266"
}
]
}
],
"references": [
{
"url": "https://jvn.jp/en/jp/JVN84326763/",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://www.skyseaclientview.net/news/240729_02/",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://jvn.jp/en/jp/JVN84326763/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.skyseaclientview.net/news/240729_02/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}