PT-2022-3354 · V-Sft · V-Sft

Michael Heinzl

·

Published

2022-04-07

·

Updated

2022-06-27

·

CVE-2022-30538

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions V-SFT versions prior to 6.1.6.0
Description The issue is related to an out-of-bounds write operation in the memory of the V-SFT graphic editor's simulator module. This could allow an attacker to gain unauthorized access to protected information or execute arbitrary code by using a specially crafted image file.
Recommendations For versions prior to 6.1.6.0, update to version 6.1.6.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the simulator module in the V-SFT graphic editor until a patch is applied. Avoid opening specially crafted image files with the affected software to minimize the risk of exploitation.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04112
CVE-2022-30538

Affected Products

V-Sft