CVE-2024-41139: High severity skysea client view vulnerability
Incorrect privilege assignment vulnerability exists in SKYSEA Client View Ver.6.010.06 to Ver.19.210.04e. If a user who can log in to the PC where the product's Windows client is installed places a specially crafted DLL file in a specific folder, arbitrary code may be executed with SYSTEM privilege.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41139?
CVE-2024-41139 has a severity rating that indicates a significant risk due to potential arbitrary code execution with SYSTEM privileges.
How do I fix CVE-2024-41139?
To mitigate CVE-2024-41139, ensure that only trusted users have access to the affected system and remove any unnecessary permissions for the specific folder.
Who is affected by CVE-2024-41139?
CVE-2024-41139 affects users of SKYSEA Client View versions 6.010.06 to 19.210.04e.
What type of vulnerability is CVE-2024-41139?
CVE-2024-41139 is categorized as an incorrect privilege assignment vulnerability.
What can be exploited in CVE-2024-41139?
CVE-2024-41139 can be exploited by placing a specially crafted DLL file in a specific folder, allowing arbitrary code execution.