CWE-622: Improper Validation of Function Hook Arguments
The product adds hooks to user-accessible API functions, but it does not properly validate the arguments. This could lead to resultant vulnerabilities.
2 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-0312 — A malicious insider can uninstall Skyhigh Client Proxy without a valid uninstall password.
- CVE-2024-0311 — A malicious insider can bypass the existing policy of Skyhigh Client Proxy without a valid release code.
Recently published
- CVE-2024-0312 — A malicious insider can uninstall Skyhigh Client Proxy without a valid uninstall password.
- CVE-2024-0311 — A malicious insider can bypass the existing policy of Skyhigh Client Proxy without a valid release code.