Executive brief
SKYSEA Client View and SKYMEC IT Manager are IT management and endpoint monitoring products used to manage Windows systems in corporate environments. A path traversal vulnerability allows an authenticated attacker on one Windows system to execute arbitrary code on another Windows system running these products that can receive UDP packets, potentially compromising critical infrastructure and enabling lateral movement across the network.
Technical details
This is a path traversal vulnerability (CWE-22/CWE-25) affecting the network communication between SKYSEA Client View and SKYMEC IT Manager components. The vulnerability requires an attacker to be authenticated on a Windows system with the affected product installed and the target system must be able to receive UDP packets from the attacker's system. An attacker can exploit this to execute arbitrary code on remote systems. This vulnerability is notably an incomplete fix for the previously disclosed CVE-2024-41726. Patches and updates are available from Sky Co., Ltd.
Affected products
- Sky SKYSEA Client View Ver.19.300.09h to Ver.21.210.01f
- Sky SKYMEC IT Manager Ver.2024.005.10a
Timeline
- 2026-08-24: disclosed
- 2026-08-24: patched: Updates and patches provided by Sky Co., Ltd.; SKYSEA Client View Ver.21.310.01a and later available