Executive brief
CGServiSign is a service application developed by Changing that manages digital signatures and credentials. Unauthenticated attackers can trick users into visiting a malicious web page, which then injects arbitrary operating system commands through the local service interface, allowing the attacker to execute code with the privileges of the affected user on their computer.
Technical details
The vulnerability is an OS command injection flaw in CGServiSign's local service interface that accepts unsanitized input from web pages. An unauthenticated remote attacker can exploit this by crafting a malicious web page that, when visited by a user, injects arbitrary OS commands executed locally. No authentication is required, but user interaction (visiting the malicious page) is a precondition; a patch is available in version 1.0.26.0625 and later.
Affected products
- Changing CGServiSign 1.0.23.1227 and earlier
Timeline
- 2026-09-23: disclosed