SKYSEA Client View および SKYMEC IT Manager に複数の脆弱性
予習
この記事のキーワード — タップで意味×5
任意
にんい
1. optional; voluntary; arbitrary; random; discretionary; facultative; spontaneous; any 2. arbitrary
×5
実行
じっこう
execution (e.g. of a plan); carrying out; practice; action; implementation; fulfillment; realization
×3
受信
じゅしん
receiving (a message, letter, email, etc.); reception (radio, TV, etc.)
×6
及び
および
and; as well as
N1×3
当該
とうがい
appropriate (e.g. authorities); concerned; relevant; said; aforementioned; competent; applicable; respective
独立行政法人情報処理推進機構(IPA)および一般社団法人JPCERT コーディネーションセンター(JPCERT/CC)は8月24日、SKYSEA Client ViewおよびSKYMEC IT Managerにおける複数の脆弱性について「Japan Vulnerability Notes(JVN)」で発表した。富士通株式会社のサイフィエフ ルスラン氏とファウストヴ デニス氏、早水優二氏が報告を行っている。影響を受けるシステムは以下の通り。
・CVE-2026-66109、CVE-2026-68960 SKYSEA Client View Ver.21.210.01fおよびそれ以前 SKYMEC IT Manager Ver.2023.225.03a、Ver.2024.005.10a
・CVE-2026-68062、CVE-2026-68959 SKYSEA Client View Ver.19.300.09hからVer.21.210.01fまで SKYMEC IT Manager Ver.2024.005.10a
・CVE-2026-69665 SKYSEA Client View Ver.21.300.12gおよびそれ以前 SKYMEC IT Manager Ver.2025.205.08aおよびそれ以前
Sky株式会社が提供するIT資産管理用ツール SKYSEA Client ViewおよびSKYMEC IT Managerには、下記の影響を受ける可能性がある複数の脆弱性が存在する。
・認可処理の欠如(CVE-2026-66109) → SYSTEM権限で任意のコードが実行される
・パストラバーサル(CVE-2026-68062) →UDPパケットを受信可能かつ当該製品がインストールされた他のWindows端末上で任意のコードが実行される
・パストラバーサル(CVE-2026-68959) →UDPパケットを受信可能かつ当該製品がインストールされた他のWindows端末上で任意のコードが実行される
・スタックベースのバッファオーバーフロー(CVE-2026-68960) →UDPパケットを受信可能かつ当該製品がインストールされた他のWindows端末上で任意のコードが実行される
・インストール時の不適切なファイルアクセス権設定(CVE-2026-69665) → SYSTEM権限で任意のコードが実行される
JVNでは、開発者が提供する情報をもとにパッチを適用するよう呼びかけている。
・CVE-2026-66109、CVE-2026-68960 SKYSEA Client View Ver.21.210.01fおよびそれ以前 SKYMEC IT Manager Ver.2023.225.03a、Ver.2024.005.10a
・CVE-2026-68062、CVE-2026-68959 SKYSEA Client View Ver.19.300.09hからVer.21.210.01fまで SKYMEC IT Manager Ver.2024.005.10a
・CVE-2026-69665 SKYSEA Client View Ver.21.300.12gおよびそれ以前 SKYMEC IT Manager Ver.2025.205.08aおよびそれ以前
Sky株式会社が提供するIT資産管理用ツール SKYSEA Client ViewおよびSKYMEC IT Managerには、下記の影響を受ける可能性がある複数の脆弱性が存在する。
・認可処理の欠如(CVE-2026-66109) → SYSTEM権限で任意のコードが実行される
・パストラバーサル(CVE-2026-68062) →UDPパケットを受信可能かつ当該製品がインストールされた他のWindows端末上で任意のコードが実行される
・パストラバーサル(CVE-2026-68959) →UDPパケットを受信可能かつ当該製品がインストールされた他のWindows端末上で任意のコードが実行される
・スタックベースのバッファオーバーフロー(CVE-2026-68960) →UDPパケットを受信可能かつ当該製品がインストールされた他のWindows端末上で任意のコードが実行される
・インストール時の不適切なファイルアクセス権設定(CVE-2026-69665) → SYSTEM権限で任意のコードが実行される
JVNでは、開発者が提供する情報をもとにパッチを適用するよう呼びかけている。
この記事の単語 (40)
×6
及び
および
and; as well as
×5
任意
にんい
1. optional; voluntary; arbitrary; random; discretionary; facultative; spontaneous; any 2. arbitrary
×5
実行
じっこう
execution (e.g. of a plan); carrying out; practice; action; implementation; fulfillment; realization
×3
以前
いぜん
ago; since; before; previous
×3
受信
じゅしん
receiving (a message, letter, email, etc.); reception (radio, TV, etc.)
×3
可能
かのう
possible; potential; practicable; feasible
×3
当該
とうがい
appropriate (e.g. authorities); concerned; relevant; said; aforementioned; competent; applicable; respective
×3
製品
せいひん
manufactured goods; finished goods; product
×3
他
ほか
1. other (place, thing, person); the rest 2. outside; beyond
×3
端末
たんまつ
1. terminal; computer terminal 2. information access device (smartphone, tablet, book-reader, etc.)
×2
複数
ふくすう
plural; multiple; several
×2
脆弱性
ぜいじゃくせい
vulnerability; weakness; fragility
×2
株式会社
かぶしきがいしゃ
stock company; corporation; kabushiki kaisha; KK
×2
影響
えいきょう
1. influence; effect 2. to influence; to affect; to have an influence on; to impact; to have an effect on
×2
提供
ていきょう
1. offer; tender; providing; supplying; making available; donating (blood, organs, etc.) 2. sponsoring (a TV program)
×2
権限
けんげん
power; authority; jurisdiction
×1
独立行政法人
どくりつぎょうせいほうじん
independent administrative corporation (institution, agency)
×1
情報処理推進機構
じょうほうしょりすいしんきこう
Information-technology Promotion Agency (organization)
×1
一般社団法人
いっぱんしゃだんほうじん
general incorporated association
×1
発表
はっぴょう
announcement; publication; presenting; statement; communique; making known; breaking (news story); expressing (one's opinion); releasing; unveiling
×1
富士通
ふじつう
Fujitsu (company)
×1
早水
はやみ
Hayami (fem; surname)
×1
優二
ゆうじ
Yuuji (given)
×1
報告
ほうこく
report; information
×1
通り
とおり
1. avenue; street; way; road 2. coming and going; street traffic
×1
資産管理
しさんかんり
asset management; asset management provision
×1
下記
かき
the following
×1
可能性
かのうせい
potentiality; likelihood; possibility; availability
×1
存在
そんざい
existence; being
×1
認可
にんか
approval; license; licence; permission
×1
処理
しょり
processing; dealing with; treatment; disposition; disposal
×1
欠如
けつじょ
lack; absence; shortage; deficiency; privation
×1
不適切
ふてきせつ
unsuitable; inappropriate; improper
×1
アクセス権
アクセスけん
right of access; access permission; access right
×1
設定
せってい
1. establishment; creation; posing (a problem); setting (movie, novel, etc.); scene 2. options setting; preference settings; configuration; setup
×1
開発者
かいはつしゃ
developer
×1
情報
じょうほう
1. information; news; intelligence; advices 2. information; data contained in characters, signals, code, etc.
×1
もと
1. origin; source 2. base; basis; foundation; root
×1
適用
てきよう
applying (e.g. a technology); adoption
×1
呼び掛ける
よびかける
1. to call out to; to hail; to address 2. to appeal