Impact
A missing authorization flaw in SKYSEA Client View and SKYMEC IT Manager allows a user who can log in to a Windows system to execute arbitrary code with SYSTEM privilege, a classic example of broken access control (CWE-862). The vulnerability can be leveraged for full system compromise, exposing all data and processes on the host.
Affected Systems
The affected products are SKYSEA Client View and SKYMEC IT Manager from Sky Co., LTD. No specific version information is provided, so any installation of these products may be vulnerable unless verified otherwise.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity level, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an authenticated session on the local Windows machine, making it a local privilege escalation scenario that can lead to severe confidentiality, integrity, and availability impacts.
OpenCVE Enrichment