PT-2018-10021 · Cncsoft+1 · Cncsoft+1

Natnael Samson

+1

·

Published

2018-08-13

·

Updated

2020-08-31

·

CVE-2018-10636

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CNCSoft versions 1.00.83 and prior ScreenEditor versions 1.00.54 and prior
Description The software has multiple stack-based buffer overflow issues due to inadequate user input validation before copying data from project files onto the stack. This could cause the software to crash and may allow an attacker to gain remote code execution with administrator privileges if exploited.
Recommendations For CNCSoft versions 1.00.83 and prior, update to a version later than 1.00.83 to resolve the issue. For ScreenEditor versions 1.00.54 and prior, update to a version later than 1.00.54 to resolve the issue. As a temporary workaround, consider disabling the use of DPB files in the ScreenEditor until a patch is available. Restrict access to the ScreenEditor to minimize the risk of exploitation.

Fix

Stack Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10636
ZDI-18-1070
ZDI-18-1071
ZDI-18-979
ZDI-18-980
ZDI-18-981
ZDI-18-982
ZDI-18-983
ZDI-18-984
ZDI-18-985
ZDI-18-986

Affected Products

Cncsoft
Screeneditor