Out-of-Bounds Read Vulnerability in CNCSoft’s ScreenEditor by CNCSoft
CVE-2018-10598

8.1HIGH

Key Information:

Vendor

Ics-cert

Vendor
CVE Published:
13 August 2018

What is CVE-2018-10598?

CNCSoft's ScreenEditor, particularly in versions 1.00.83 and prior when used with ScreenEditor version 1.00.54, contains two significant out-of-bounds read vulnerabilities. These vulnerabilities result from insufficient user input validation when processing project files. An attacker exploiting these flaws could induce a software crash and potentially achieve remote code execution with elevated privileges, posing a substantial risk to users.

Affected Version(s)

CNCSoft with ScreenEditor CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.