PT-2024-38031 · Unknown · Control Fpwin Pro

Michael Heinzl

·

Published

2024-08-21

·

Updated

2024-08-25

·

CVE-2024-7013

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Control FPWIN Pro versions 7.7.2.0 and all previous versions
Description A stack-based buffer overflow in Control FPWIN Pro may allow attackers to execute arbitrary code via a specially crafted project file. This issue can be exploited by attackers to gain remote code execution.
Recommendations For Control FPWIN Pro versions 7.7.2.0 and all previous versions, patch immediately and validate project files to prevent exploitation. As a temporary workaround, consider restricting access to project files until a patch is applied.

Fix

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-7013

Affected Products

Control Fpwin Pro