Vulnerabilities > CVE-2019-10947 - Out-of-bounds Write vulnerability in Deltaww Cncsoft Screeneditor 1.00.88
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. This may occur because CNCSoft lacks user input validation before copying data from project files onto the stack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Common Weakness Enumeration (CWE)
References
- https://ics-cert.us-cert.gov/advisories/ICSA-19-106-01
- https://www.zerodayinitiative.com/advisories/ZDI-19-417/
- https://www.zerodayinitiative.com/advisories/ZDI-19-410/
- https://www.zerodayinitiative.com/advisories/ZDI-19-404/
- https://www.zerodayinitiative.com/advisories/ZDI-19-403/
- https://www.zerodayinitiative.com/advisories/ZDI-19-402/
- https://www.zerodayinitiative.com/advisories/ZDI-19-401/
- https://www.zerodayinitiative.com/advisories/ZDI-19-400/
- https://www.zerodayinitiative.com/advisories/ZDI-19-399/
- http://www.securityfocus.com/bid/107989