Heap-based Buffer Overflow in PRJ File Parsing Affects Vendor Application
CVE-2025-49850
8.4HIGH
What is CVE-2025-49850?
A vulnerability exists in the application that processes PRJ files, where a lack of proper validation of user-supplied data leads to a Heap-based Buffer Overflow. This flaw can potentially cause memory corruption by allowing the application to read and write beyond the limits of allocated data structures, exposing it to various security risks. Proper data handling practices are essential to mitigate the impact.
Affected Version(s)
GMWin 4 Version 4.18
References
CVSS V4
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michael Heinzl reported these vulnerabilities to CISA.