CVE-2026-76148

8.4

SASAKI · CorvusSKK

CorvusSKK is vulnerable to code injection, which may allow an attacker to execute arbitrary code on the host system.

Executive summary

A code injection vulnerability in SASAKI CorvusSKK poses a high risk of arbitrary code execution for affected users.

Vulnerability

This is a code injection vulnerability (CWE-94) that can be triggered by a local attacker. The vulnerability requires user interaction to facilitate the attack vector.

Business impact

Successful exploitation allows an attacker to execute arbitrary code, potentially leading to full system compromise. With a CVSS score of 8.4, this vulnerability represents a significant threat to data confidentiality, integrity, and availability within the local environment.

Remediation

Immediate Action: Update the CorvusSKK software to version 3.3.4 or later immediately.

Proactive Monitoring: Monitor system logs for unexpected process execution or abnormal application behavior following software updates.

Compensating Controls: Ensure that users operate with the principle of least privilege to limit the potential impact of arbitrary code execution if the application is compromised.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

The high severity of this vulnerability necessitates an immediate update to the patched version. Administrators should prioritize deploying version 3.3.4 to eliminate the risk of code injection and prevent potential system compromise.