RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is exploited, unintended processes may be executed in the sandbox environment. Even if malware is executed in the sandbox environment, it does not compromise the client's local environment. However, information in the sandbox environment may be disclosed to outside or behaviors of the sandbox environment may be violated by tampering registry.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2024-42526 | RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is exploited, unintended processes may be executed in the sandbox environment. Even if malware is executed in the sandbox environment, it does not compromise the client's local environment. However, information in the sandbox environment may be disclosed to outside or behaviors of the sandbox environment may be violated by tampering registry. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://jscom.jp/news-20240918/ |
![]() ![]() |
https://jvn.jp/en/jp/JVN39280069/ |
![]() ![]() |
History
Tue, 01 Oct 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jscom
Jscom revoworks Cloud Client |
|
CPEs | cpe:2.3:a:jscom:revoworks_cloud_client:*:*:*:*:*:*:*:* | |
Vendors & Products |
Jscom
Jscom revoworks Cloud Client |
|
Metrics |
ssvc
|
Tue, 01 Oct 2024 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is exploited, unintended processes may be executed in the sandbox environment. Even if malware is executed in the sandbox environment, it does not compromise the client's local environment. However, information in the sandbox environment may be disclosed to outside or behaviors of the sandbox environment may be violated by tampering registry. | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-10-01T14:13:05.394Z
Reserved: 2024-09-27T02:31:41.840Z
Link: CVE-2024-47560

Updated: 2024-10-01T14:12:59.978Z

Status : Awaiting Analysis
Published: 2024-10-01T02:15:10.143
Modified: 2024-10-04T13:51:25.567
Link: CVE-2024-47560

No data.

No data.