CVE-2024-40722

Published Aug 2, 2024

Last updated 10 months ago

Overview

Description
The specific API in TCBServiSign Windows Version from CHANGING Information Technology does does not properly validate the length of server-side input. When a user visits a spoofed website, unauthenticated remote attackers can cause a stack-based buffer overflow in the TCBServiSign, temporarily disrupting its service.
Source
twcert@cert.org.tw
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
4.3
Impact score
1.4
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Severity
MEDIUM

Weaknesses

nvd@nist.gov
CWE-787
twcert@cert.org.tw
CWE-121

Social media

Hype score
Not currently trending

Configurations