Back

HIGH

CHANGING Information Technology TCBServiSign Windows Version - Improper Input Validation

Published Aug 2, 2024

Description

The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can modify the `HKEY_CURRENT_USER` registry to execute arbitrary commands.

Affected products

Remediation

Vendor solution

Update to version 1.0.24.0318 or later.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Aug 2, 2024
Updated Aug 2, 2024
Reserved Jul 9, 2024
CISA Vulnrichment
Updated Aug 2, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner twcert
Published Aug 2, 2024
Updated Aug 2, 2024
Exploited since n/a
EUVD-2024-38585