CVE-2024-24964

Improper access control vulnerability exists in the resident process of SKYSEA Client View versions from Ver.11.220 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the product's Windows client is installed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:skygroup:skysea_client_view:*:*:*:*:*:*:*:*

History

23 May 2025, 14:44

Type Values Removed Values Added
CPE cpe:2.3:a:skygroup:skysea_client_view:*:*:*:*:*:*:*:*
First Time Skygroup skysea Client View
Skygroup
References () https://jvn.jp/en/jp/JVN54451757/ - () https://jvn.jp/en/jp/JVN54451757/ - Third Party Advisory
References () https://www.skyseaclientview.net/news/240307_01/ - () https://www.skyseaclientview.net/news/240307_01/ - Vendor Advisory
CWE NVD-CWE-Other

21 Nov 2024, 09:00

Type Values Removed Values Added
References () https://jvn.jp/en/jp/JVN54451757/ - () https://jvn.jp/en/jp/JVN54451757/ -
References () https://www.skyseaclientview.net/news/240307_01/ - () https://www.skyseaclientview.net/news/240307_01/ -

07 Nov 2024, 17:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.3
Summary
  • (es) Existe una vulnerabilidad de control de acceso inadecuado en el proceso residente de las versiones de SKYSEA Client View desde la versión 11.220 anterior a la versión 19.2. Si se explota esta vulnerabilidad, un usuario que pueda iniciar sesión en la PC donde está instalado el cliente Windows del producto puede ejecutar un proceso arbitrario con privilegios de SYSTEM.

12 Mar 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-12 08:15

Updated : 2025-05-23 14:44


NVD link : CVE-2024-24964

Mitre link : CVE-2024-24964

CVE.ORG link : CVE-2024-24964


JSON object : View

Products Affected

skygroup

  • skysea_client_view