RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is exploited, unintended processes may be executed in the sandbox environment. Even if malware is executed in the sandbox environment, it does not compromise the client's local environment. However, information in the sandbox environment may be disclosed to outside or behaviors of the sandbox environment may be violated by tampering registry.
History

Tue, 01 Oct 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Jscom
Jscom revoworks Cloud Client
CPEs cpe:2.3:a:jscom:revoworks_cloud_client:*:*:*:*:*:*:*:*
Vendors & Products Jscom
Jscom revoworks Cloud Client
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Oct 2024 01:30:00 +0000

Type Values Removed Values Added
Description RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is exploited, unintended processes may be executed in the sandbox environment. Even if malware is executed in the sandbox environment, it does not compromise the client's local environment. However, information in the sandbox environment may be disclosed to outside or behaviors of the sandbox environment may be violated by tampering registry.
Weaknesses CWE-863
References
Metrics cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2024-10-01T01:00:23.083Z

Updated: 2024-10-01T14:13:05.394Z

Reserved: 2024-09-27T02:31:41.840Z

Link: CVE-2024-47560

cve-icon Vulnrichment

Updated: 2024-10-01T14:12:59.978Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-01T02:15:10.143

Modified: 2024-10-04T13:51:25.567

Link: CVE-2024-47560

cve-icon Redhat

No data.