PT-2020-6284 · Unknown · Igss Definition

Published

2020-11-10

·

Updated

2022-01-01

·

CVE-2020-7551

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IGSS Definition (Def.exe) version 14.0.0.20247
Description A vulnerability exists in IGSS Definition that could cause Remote Code Execution when a malicious CGF (Configuration Group File) file is imported. This issue is related to an out-of-bounds write in memory, which may allow an attacker to execute arbitrary code. The vulnerability is associated with the improper restriction of operations within the bounds of a memory buffer.
Recommendations For IGSS Definition version 14.0.0.20247, consider disabling the import of CGF files until a patch is available to prevent potential Remote Code Execution. Restrict access to the Def.exe file to minimize the risk of exploitation. Avoid using malicious CGF files in the affected IGSS Definition version. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03890
CVE-2020-7551
ZDI-21-126

Affected Products

Igss Definition