CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.8. It affects Windows. It may be remotely exploitable.
CVE
CVE-2024-40720
Severity
HIGH
CVSS
8.8
EPSS
0.59%
Windows
Original NVD Description
The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can modify the `HKEY_CURRENT_USER` registry to execute arbitrary commands.
Related CVEs
Other vulnerabilities affecting the same vendor(s)