Impact
SKYSEA Client View and SKYMEC IT Manager allow an attacker to execute arbitrary code with SYSTEM privilege on a Windows system after authentication. This originates from incorrect default permissions that grant higher access than required. The resulting privilege escalation could compromise the entire host, affecting confidentiality, integrity, and availability of all data and services.
Affected Systems
Sky Co., LTD products SKYMEC IT Manager and SKYSEA Client View are affected. The vulnerability applies to any version of these applications installed on Windows systems, as no precise version range is provided.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker who can log in to the Windows machine, implying local or remote authenticated access. Once authenticated, the misconfigured permissions enable the attacker to elevate privileges to SYSTEM and run arbitrary code.
OpenCVE Enrichment