Sky Co., Ltd. SKYSEA Client View and SKYMEC IT Manager Improper File Access Permission Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability exists in SKYSEA Client View versions through 21.200.07j and SKYMEC IT Manager versions through 2024.005.10a, both provided by Sky Co., Ltd. These applications improperly configure file access permissions in the installation folder, allowing non-administrative users to manipulate or place arbitrary files. This could lead to the execution of arbitrary code with administrative privileges.

Impact

Exploitation of this vulnerability could allow non-administrative users to execute arbitrary code with administrative privileges on the affected system.

Remediation

Users of SKYSEA Client View can update to version 21.210.01f or later, or apply the available patch through the Master Server. SKYMEC IT Manager users should apply the provided patch via the Master Server. For both applications, if a departmental installer was created before this update, it should be re-created.

Added: Apr 20, 2026, 9:42 AM
Updated: Apr 20, 2026, 9:42 AM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
3.5
remediation
7.7
relevance
6.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.