PT-2018-9989 · Cncsoft · Cncsoft+1

Mat Powell

·

Publicado

2018-08-13

·

Atualizado

2019-10-09

·

CVE-2018-10598

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions: CNCSoft versions 1.00.83 and prior CNCSoft ScreenEditor versions 1.00.54 and prior
Description: The issue is related to two out-of-bounds read vulnerabilities that could cause the software to crash due to lacking user input validation for processing project files. This may allow an attacker to gain remote code execution with administrator privileges if exploited.
Recommendations: For CNCSoft versions 1.00.83 and prior, update to a version that includes input validation for project files to prevent out-of-bounds read vulnerabilities. For CNCSoft ScreenEditor versions 1.00.54 and prior, restrict access to project files until a patch is available that addresses the out-of-bounds read vulnerabilities.

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-10598
ZDI-18-987
ZDI-18-988

Produtos afetados

Cncsoft
Cncsoft Screeneditor