Vulnerabilities > CVE-2018-7817 - Use After Free vulnerability in Schneider-Electric Zelio Soft 2 4.6/5.0/5.1

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
schneider-electric
CWE-416

Summary

A Use After Free (CWE-416) vulnerability exists in Zelio Soft 2 v5.1 and prior versions which could cause remote code execution when opening a specially crafted Zelio Soft project file.

Common Weakness Enumeration (CWE)