CVE-2024-40719: Changingtec Tcb Servisign

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

The encryption strength of the authorization keys in CHANGING Information Technology TCBServiSign Windows Version is insufficient. When a remote attacker tricks a victim into visiting a malicious website, TCBServiSign will treat that website as a legitimate server and interact with it.

Affected products

  • Changingtec Tcb Servisign: before 1.0.24.0318 (fixed in 1.0.24.0318)

Published 2024-08-02. Last modified 2026-06-17.