Vulnerability CVE-2024-40719


Published: 2024-08-02

Description:
The encryption strength of the authorization keys in CHANGING Information Technology TCBServiSign Windows Version is insufficient. When a remote attacker tricks a victim into visiting a malicious website, TCBServiSign will treat that website as a legitimate server and interact with it.

Type:

CWE-326

(Inadequate Encryption Strength)

 References:
https://www.twcert.org.tw/tw/cp-132-7964-5b266-1.html
https://www.twcert.org.tw/en/cp-139-7970-e8ac5-2.html

Copyright 2024, cxsecurity.com

 

Back to Top