CVE-2024-24964

Improper access control vulnerability exists in the resident process of SKYSEA Client View versions from Ver.11.220 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the product's Windows client is installed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:skygroup:skysea_client_view:*:*:*:*:*:*:*:*

History

23 May 2025, 14:44

Type Values Removed Values Added
CPE cpe:2.3:a:skygroup:skysea_client_view:*:*:*:*:*:*:*:*
First Time Skygroup
Skygroup skysea Client View
CWE NVD-CWE-Other
References () https://jvn.jp/en/jp/JVN54451757/ - () https://jvn.jp/en/jp/JVN54451757/ - Third Party Advisory
References () https://www.skyseaclientview.net/news/240307_01/ - () https://www.skyseaclientview.net/news/240307_01/ - Vendor Advisory

21 Nov 2024, 09:00

Type Values Removed Values Added
References () https://jvn.jp/en/jp/JVN54451757/ - () https://jvn.jp/en/jp/JVN54451757/ -
References () https://www.skyseaclientview.net/news/240307_01/ - () https://www.skyseaclientview.net/news/240307_01/ -

07 Nov 2024, 17:35

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de control de acceso inadecuado en el proceso residente de las versiones de SKYSEA Client View desde la versión 11.220 anterior a la versión 19.2. Si se explota esta vulnerabilidad, un usuario que pueda iniciar sesión en la PC donde está instalado el cliente Windows del producto puede ejecutar un proceso arbitrario con privilegios de SYSTEM.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.3

12 Mar 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-12 08:15

Updated : 2025-05-23 14:44


NVD link : CVE-2024-24964

Mitre link : CVE-2024-24964

CVE.ORG link : CVE-2024-24964


JSON object : View

Products Affected

skygroup

  • skysea_client_view