Impact
A code injection flaw in CorvusSKK permits an attacker to embed and execute malicious code within the application’s environment. This vulnerability is classified as CWE‑94 and can lead to complete compromise of confidentiality, integrity, and availability if exploited, effectively providing remote code execution capabilities.
Affected Systems
The vulnerability affects the CorvusSKK application produced by SASAKI Nobuyuki. No specific product versions are detailed in the advisory, so all current installations are considered potentially exposed until confirmed patched.
Risk and Exploitability
The CVSS score of 8.4 signals a high‑severity risk. No EPSS data is available, and the issue is not currently listed in CISA KEV. Exploitation likely requires access to input data that the application processes unsafely; once triggered, arbitrary code can run in the application’s context. Given the severe impact and lack of known mitigation, unpatched systems face a substantial risk of compromise.
OpenCVE Enrichment