← Vulnerability feed

Vulnerability record · CVE-2024-41143 · published 29 July 2024

CVE-2024-41143: Skygroup skysea client view origin validation error vulnerability

Skygroup · Skysea Client View

Origin validation error vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the product's Windows client is installed.

7.8 CVSS 3.1 High EPSS 0.12% · top 98.5% CWE-346 · Origin validation error
7.8CVSS 3.1 base score
0.12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Origin validation error vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the product's Windows client is installed.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-41143 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-7836SKYSEA Client View improper authentication enables remote code executionSKYSEA Client View Ver.11.221.03 and earlier contains an improper authentication flaw (CWE-287) in how the management console program processes authe…KEVEPSS 19%analysed8.5CVE-2026-39454Skygroup skymec it manager incorrect default permissions vulnerabilitySKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A …EPSS 0.15%7.8CVE-2024-41139Skygroup skysea client view vulnerabilityIncorrect privilege assignment vulnerability exists in SKYSEA Client View Ver.6.010.06 to Ver.19.210.04e. If a user who can log in to the PC where th…EPSS 0.18%7.8CVE-2024-21805Skygroup skysea client view improper access control vulnerabilityImproper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If this vulnera…EPSS 0.24%7.8CVE-2021-20616Skygroup skysea client view uncontrolled search path element vulnerabilityUntrusted search path vulnerability in the installer of SKYSEA Client View Ver.1.020.05b to Ver.16.001.01g allows an attacker to gain privileges via …EPSS 0.32%7.8CVE-2020-5617Skygroup skysea client view improper privilege management vulnerabilityPrivilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unauthorized privileges and modify…EPSS 0.34%7.5CVE-2024-41726Skygroup skysea client view path traversal vulnerabilityPath traversal vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary executable…EPSS 0.62%6.3CVE-2024-24964Skygroup skysea client view vulnerabilityImproper access control vulnerability exists in the resident process of SKYSEA Client View versions from Ver.11.220 prior to Ver.19.2. If this vulner…EPSS 0.41%

Source: NIST National Vulnerability Database (record CVE-2024-41143), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.