Executive brief
SKYSEA Client View and SKYMEC IT Manager are Windows-based IT administration and endpoint management tools used by organizations to manage client computers and security policies. This path traversal vulnerability allows an attacker who has logged into a Windows system with these products installed to execute arbitrary code on other networked Windows systems running the affected software, provided those systems can receive UDP packets. This represents a significant lateral movement risk in enterprise environments.
Technical details
This vulnerability is a path traversal (CWE-22) that results from an incomplete fix for a previous vulnerability (CVE-2024-41726). The flaw allows an authenticated local attacker to craft malicious input that bypasses file path validation, enabling arbitrary code execution on remote systems via UDP communication. The attack requires the attacker to have login access to a Windows system where the product is installed, and the target system must be able to receive UDP packets from that system. Patches are available from the vendor; SKYSEA Client View users should update to version 21.310.01a or later, and SKYMEC IT Manager users should apply the provided fix module.
Affected products
- Sky SKYSEA Client View 19.300.09h through 21.210.01f
- Sky SKYMEC IT Manager 2024.005.10a
Timeline
- 2026-08-24: disclosed
- 2026-08-25: advisory
- 2026-08-24: patched: SKYSEA Client View 21.310.01a and later; SKYMEC IT Manager fixes available