Vulnerability in TPEditor Affects Project File Processing
CVE-2020-27288

7.8HIGH

Key Information:

Vendor

Deltaww

Status
Vendor
CVE Published:
26 January 2021

What is CVE-2020-27288?

An untrusted pointer dereference vulnerability has been discovered in TPEditor, which affects versions 1.98 and earlier. This flaw allows an attacker to create a malicious project file that, when opened by the TPEditor application, can lead to arbitrary code execution on the user's system. This exposes users to significant security risks as the attacker can potentially gain control over the affected device.

Affected Version(s)

TPEditor v1.98 and prior

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.