Описание
The affected product is vulnerable to an out-of-bounds write while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.
The affected product is vulnerable to an out-of-bounds write while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2022-23985
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-055-01
- https://www.zerodayinitiative.com/advisories/ZDI-22-432
- https://www.zerodayinitiative.com/advisories/ZDI-22-433
- https://www.zerodayinitiative.com/advisories/ZDI-22-434
- https://www.zerodayinitiative.com/advisories/ZDI-22-437
- https://www.zerodayinitiative.com/advisories/ZDI-22-438
- https://www.zerodayinitiative.com/advisories/ZDI-22-440
Связанные уязвимости
CVSS3: 7.8
nvd
почти 4 года назад
The affected product is vulnerable to an out-of-bounds write while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.