Executive brief
SKYSEA Client View and SKYMEC IT Manager, which are tools used by organizations to manage their IT assets and computers, contain a security flaw in how they are installed on a system. Because the software's installation folder is not properly secured, a standard user without administrative rights can modify or add files to that folder. This could allow an attacker who already has basic access to a computer to take full control of the system with administrative privileges, potentially leading to data theft or complete system compromise.
Technical details
A local privilege escalation vulnerability exists in SKYSEA Client View and SKYMEC IT Manager due to incorrect default permissions (CWE-276) assigned to the product's installation folder. The root cause is an insecure ACL configuration that allows non-administrative users to write, modify, or replace files within the application directory. An attacker with low-privileged local access can exploit this by placing malicious binaries or DLLs in the folder, which are then executed by the application's high-privileged services. This results in arbitrary code execution with administrative or SYSTEM-level privileges. The vendor has released updates and patches to address this issue.
Affected products
- Sky Co.,LTD. SKYSEA Client View Ver.21.200.07j and earlier
- Sky Co.,LTD. SKYMEC IT Manager Ver.2024.005.10a and earlier
Timeline
- 2026-04-20: disclosed
- 2026-04-20: advisory