Описание
CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has two out-of-bounds read vulnerabilities could cause the software to crash due to lacking user input validation for processing project files. Which may allow an attacker to gain remote code execution with administrator privileges if exploited.
Ссылки
- Third Party AdvisoryVDB Entry
- MitigationThird Party AdvisoryUS Government Resource
- Third Party AdvisoryVDB Entry
- MitigationThird Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 1.00.83 (включая)
Одно из
cpe:2.3:a:deltaww:cncsoft:*:*:*:*:*:*:*:*
cpe:2.3:a:deltaww:screeneditor:1.00.54:*:*:*:*:*:*:*
EPSS
Процентиль: 80%
0.01356
Низкий
8.1 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-125
CWE-125
Связанные уязвимости
CVSS3: 8.1
github
больше 3 лет назад
CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has two out-of-bounds read vulnerabilities could cause the software to crash due to lacking user input validation for processing project files. Which may allow an attacker to gain remote code execution with administrator privileges if exploited.
EPSS
Процентиль: 80%
0.01356
Низкий
8.1 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-125
CWE-125