Description
Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.
Problem types
Product status
Any version before 1.6.1
Credits
Natnael Samson working with Trend Micro Zero Day Initiative
CISA
References
filecenter.deltaww.com/...-Of-Bounds Write Vulnerability.pdf