Home
HIGH: 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HDefault status
unaffected
Any version before 2.1.0.27
affected
Description
Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.
Problem types
Product status
Any version before 2.1.0.27
Credits
Kholoud Altookhy from Trend Micro's Zero Day Initiative
CISA
References
filecenter.deltaww.com/...File Parsing Memory Corruption.pdf