started · updated
Sky Co., Ltd. IT management tools face multiple vulnerabilities
Multiple vulnerabilities have been identified in SKYSEA Client View and SKYMEC IT Manager, IT asset management tools provided by Sky Co., Ltd. The flaws were reported via Japan Vulnerability Notes (JVN) by researchers from Fujitsu Limited.
The vulnerabilities include issues such as lack of authorization (CVE-2026-66109), path traversal (CVE-2026-68062, CVE-2026-68959), stack-based buffer overflow (CVE-2026-68960), and improper file access rights during installation (CVE-2026-69665).
An attacker with login access to a Windows terminal where these products are installed could potentially execute arbitrary code with SYSTEM privileges or execute code on other Windows terminals via UDP packets. Users are urged to apply patches provided by the developer.