The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can cause the TCBServiSign to load a DLL from an arbitrary path.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tcb_servisign | Changingtec | * | 1.0.24.0318 (excluding) |