Double Free Vulnerability in Kostac PLC Programming Software from Kostac
CVE-2023-41374
7.8HIGH
Key Information:
- Vendor
- CVE Published:
- 20 September 2023
What is CVE-2023-41374?
A double free vulnerability has been identified in Kostac PLC Programming Software versions 1.6.11.0 and earlier, which allows for arbitrary code execution. This occurs when a user opens a specially crafted KPP project file, saved with an earlier version (1.6.9.0 and prior). It is critical to update to version 1.6.10.0 or later to prevent project file alterations and mitigate this risk. For those using affected versions, re-saving project files with the latest version is strongly recommended.
Affected Version(s)
Kostac PLC Programming Software Version 1.6.11.0 and earlier