First published: Wed Jan 13 2021(Updated: )
Untrusted search path vulnerability in the installer of SKYSEA Client View Ver.1.020.05b to Ver.16.001.01g allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
SKYSEA Client View | >=1.020.05b<=16.001.01g |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-20616 is high with a CVSS score of 7.8.
CVE-2021-20616 is an untrusted search path vulnerability in the installer of SKYSEA Client View, allowing an attacker to gain privileges via a Trojan horse DLL.
CVE-2021-20616 affects SKYSEA Client View versions 1.020.05b to 16.001.01g.
At the moment, there is no specific fix or patch available for CVE-2021-20616. It is recommended to follow any updates from the vendor.
The CWE ID for CVE-2021-20616 is CWE-427 (Uncontrolled Search Path Element).