Impact
A path traversal flaw exists in SKYSEA Client View and SKYMEC IT Manager that can be abused by an attacker who has local login access to a Windows system running the affected software. By crafting a malicious path reference, the attacker can cause the application to create or modify files that enable execution of arbitrary code on a different Windows system that also hosts the software and is reachable via UDP. The flaw is a consequence of an incomplete fix for a prior CVE and therefore may not be fully mitigated in all installations.
Affected Systems
The vulnerability is present in Sky Co., LTD: SKYMEC IT Manager and Sky Co., LTD: SKYSEA Client View. Specific product versions are not disclosed in the data provided.
Risk and Exploitability
The CVSS score is 5.8, indicating a medium severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. Attack requires the attacker to log into a Windows host with the product installed, then target a separate host that receives UDP packets from it. If these conditions are met, exploit can lead to remote code execution.
OpenCVE Enrichment