CVE-2024-40720
02.08.2024, 11:16
The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can modify the `HKEY_CURRENT_USER` registry to execute arbitrary commands.Enginsight
Vendor | Product | Version |
---|---|---|
changingtec | tcb_servisign | 𝑥 < 1.0.24.0318 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration