Executive brief
SKYSEA Client View is endpoint management software deployed across Windows corporate networks to monitor and manage devices. A missing authorization check allows any logged-in user to execute arbitrary code with system-level privileges, enabling complete system compromise and potential lateral movement to other managed endpoints.
Technical details
This vulnerability is a missing authorization flaw (CWE-862) in SKYSEA Client View and SKYMEC IT Manager that allows privilege escalation. The affected component fails to properly validate that a user has the required privileges before allowing execution of sensitive operations. An attacker with standard user-level access to a Windows system running the affected software can invoke privileged functionality without authentication, resulting in arbitrary code execution with SYSTEM privileges. The vulnerability affects SKYSEA Client View version 21.210.01f and earlier, as well as SKYMEC IT Manager versions 2023.225.03a and 2024.005.10a. Patches and updates are available from Sky Co., Ltd.
Affected products
- Sky SKYSEA Client View Ver. 21.210.01f and earlier
- Sky SKYMEC IT Manager Ver. 2023.225.03a, 2024.005.10a
Timeline
- 2026-08-24: disclosed
- 2026-08-25: advisory