CVE-2024-21805

HIGH

SKYSEA Client View 16.100.06f-19.2 - Authenticated Arbitrary File Write and Privilege Escalation via DLL Placement

Title source: llm
STIX 2.1

Description

Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary file may be placed in the specific folder by a user who can log in to the PC where the product's Windows client is installed. In case the file is a specially crafted DLL file, arbitrary code may be executed with SYSTEM privilege.

References (2)

Core 2
Core References
Third Party Advisory
https://jvn.jp/en/jp/JVN54451757/

Scores

CVSS v3 7.8
EPSS 0.0024
EPSS Percentile 14.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
skygroup/skysea_client_view 16.100.06f - 19.300.09h
Published Mar 12, 2024
Tracked Since Feb 18, 2026