PT-2019-12851 · Sweetscape · 010 Editor

Publicado

2019-06-05

·

Atualizado

2020-08-24

·

CVE-2019-12553

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 010 Editor version 9.0.1
Description The issue arises from improper validation of arguments in the internal implementation of the StrCat function, which is provided by the scripting engine. This allows an attacker to overwrite arbitrary memory, potentially leading to code execution.
Recommendations For version 9.0.1, consider disabling the StrCat function as a temporary workaround until a patch is available. Restrict access to the scripting engine to minimize the risk of exploitation.

Exploit

Correção

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-12553

Produtos afetados

010 Editor