Use After Free Vulnerability in Kostac PLC Programming Software
CVE-2023-41375

7.8HIGH

What is CVE-2023-41375?

A use after free vulnerability in Kostac PLC Programming Software allows for arbitrary code execution when users open specially crafted project files. This issue arises when project files, saved using Kostac PLC Programming Software Version 1.6.9.0 or earlier, are parsed. To prevent exploitation, users are advised to save these files using Version 1.6.10.0 or later, which contains appropriate safeguards against project file alterations.

Affected Version(s)

Kostac PLC Programming Software Version 1.6.11.0 and earlier

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.