Double Free Vulnerability in Kostac PLC Programming Software from Kostac
CVE-2023-41374

7.8HIGH

What is CVE-2023-41374?

A double free vulnerability has been identified in Kostac PLC Programming Software versions 1.6.11.0 and earlier, which allows for arbitrary code execution. This occurs when a user opens a specially crafted KPP project file, saved with an earlier version (1.6.9.0 and prior). It is critical to update to version 1.6.10.0 or later to prevent project file alterations and mitigate this risk. For those using affected versions, re-saving project files with the latest version is strongly recommended.

Affected Version(s)

Kostac PLC Programming Software Version 1.6.11.0 and earlier

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.