VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without first checking for validity, allowing attacker supplied input to be written to known memory locations. This may cause the program to crash or allow remote code execution.
References
| Link | Resource |
|---|---|
| https://ics-cert.us-cert.gov/advisories/ICSA-18-333-01 | Third Party Advisory US Government Resource |
| http://www.securityfocus.com/bid/106071 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2018-11-30 10:29
Updated : 2018-12-27 09:46
NVD link : CVE-2018-18987
Mitre link : CVE-2018-18987
JSON object : View
CWE
CWE-502
Deserialization of Untrusted Data
Products Affected
invt
- vt-designer


