Description
The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can modify the `HKEY_CURRENT_USER` registry to execute arbitrary commands.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to version 1.0.24.0318 or later.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-38585 | The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can modify the `HKEY_CURRENT_USER` registry to execute arbitrary commands. |
References
History
Fri, 09 Aug 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Changingtec
Changingtec tcb Servisign |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:changingtec:tcb_servisign:*:*:*:*:*:windows:*:* | |
| Vendors & Products |
Changingtec
Changingtec tcb Servisign |
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-02T16:08:16.108Z
Reserved: 2024-07-09T03:30:54.516Z
Link: CVE-2024-40720
Updated: 2024-08-02T16:08:12.763Z
Status : Analyzed
Published: 2024-08-02T11:16:42.763
Modified: 2024-08-09T14:36:35.047
Link: CVE-2024-40720
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD