CVE-2024-40721
02.08.2024, 11:16
The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can cause the TCBServiSign to load a DLL from an arbitrary path.Enginsight
Vendor | Product | Version |
---|---|---|
changingtec | tcb_servisign | 𝑥 < 1.0.24.0318 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration