Out-of-Bounds Write Vulnerability in V-SFT Graphic Editor by Fujielectric
CVE-2022-30538

7.8HIGH

What is CVE-2022-30538?

An out-of-bounds write vulnerability has been identified in the simulator module of the V-SFT graphic editor. This issue affects versions before v6.1.6.0 and may allow attackers to exploit this flaw through specially crafted image files. When a user opens a malicious file, it can lead to information disclosure or arbitrary code execution, putting the integrity of user systems at risk. Addressing this vulnerability is crucial for maintaining secure operations within environments utilizing V-SFT.

Affected Version(s)

V-SFT versions prior to v6.1.6.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.