Remote Code Execution Vulnerability in Fuji Electric Tellus Lite V-Simulator 5
CVE-2024-11803

7.8HIGH

Key Information:

Vendor
CVE Published:
28 November 2024

What is CVE-2024-11803?

The vulnerability in Fuji Electric Tellus Lite V-Simulator 5 originates from the improper handling of V8 file parsing. This flaw allows remote attackers to execute arbitrary code when a victim interacts with a malicious page or file. The specific problem arises from inadequate validation of user-supplied data, which can lead to a write operation beyond the boundaries of allocated memory, potentially compromising the current process's execution context. Successful exploitation requires user interaction, making awareness and caution critical in preventing such attacks.

Affected Version(s)

Tellus Lite 4.0.20.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.