Executive brief
SKYSEA Client View, a popular IT asset management and log monitoring software, contains a critical security flaw in how it verifies users. An attacker can bypass security checks to remotely take control of computers running the software without needing a password. This could lead to a total compromise of the corporate network, data theft, or the deployment of ransomware.
Technical details
An improper authentication vulnerability (CWE-287) exists in SKYSEA Client View versions 11.221.03 and earlier. The flaw resides in the management console program's handling of TCP connections, where authentication checks are incorrectly processed. A remote, unauthenticated attacker can exploit this by sending specially crafted packets to the management port, leading to arbitrary code execution with system-level privileges. This vulnerability has been observed in the wild and is included in the CISA Known Exploited Vulnerabilities (KEV) catalog. Users should update to a patched version or apply vendor-recommended mitigations immediately.
Affected products
- Sky Co., Ltd. SKYSEA Client View Ver.11.221.03 and earlier
Timeline
- 2016-12-21: advisory: Vendor advisory released by Sky Co., Ltd.
- 2017-06-09: disclosed: NVD published date
- 2025-10-14: kev added: Added to CISA Known Exploited Vulnerabilities catalog