8.8
CVE-2024-40720
- EPSS 3.8%
- Veröffentlicht 02.08.2024 11:16:42
- Zuletzt bearbeitet 09.08.2024 14:36:35
- Quelle twcert@cert.org.tw
- CVE-Watchlists
- Unerledigt
The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can modify the `HKEY_CURRENT_USER` registry to execute arbitrary commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Changingtec ≫ Tcb Servisign SwPlatformwindows Version < 1.0.24.0318
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.8% | 0.878 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| twcert@cert.org.tw | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.