PT-2023-2921 · Cx-Drive · Cx-Drive

Michael Heinzl

·

Published

2023-03-15

·

Updated

2023-08-02

·

CVE-2023-27385

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CX-Drive versions V3.01 and earlier
Description A heap-based buffer overflow issue exists, allowing arbitrary code execution and/or information disclosure when a user opens a specially crafted SDD file.
Recommendations For CX-Drive versions V3.01 and earlier, consider restricting access to SDD files until a patch is available. As a temporary workaround, avoid using SDD files in CX-Drive until the issue is resolved.

Fix

Memory Corruption

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2023-02892
CVE-2023-27385

Affected Products

Cx-Drive