Description
The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can cause the TCBServiSign to load a DLL from an arbitrary path.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to version 1.0.24.0318 or later.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-38586 | The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can cause the TCBServiSign to load a DLL from an arbitrary path. |
References
History
Fri, 09 Aug 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Changingtec tcb Servisign
|
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:changingtec:tcb_servisign:*:*:*:*:*:windows:*:* | |
| Vendors & Products |
Changingtec tcb Servisign
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-02T13:47:51.345Z
Reserved: 2024-07-09T03:30:54.516Z
Link: CVE-2024-40721
Updated: 2024-08-02T13:47:46.523Z
Status : Analyzed
Published: 2024-08-02T11:16:43.020
Modified: 2024-08-09T14:36:58.623
Link: CVE-2024-40721
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD