CVE-2018-10598: Input Validation
CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has two out-of-bounds read vulnerabilities could cause the software to crash due to lacking user input validation for processing project files. Which may allow an attacker to gain remote code execution with administrator privileges if exploited.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-10598?
CVE-2018-10598 is a vulnerability in CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 that allows an attacker to gain remote code execution with administrator privileges.
What is the severity of CVE-2018-10598?
The severity of CVE-2018-10598 is high, with a CVSS score of 8.1.
How does CVE-2018-10598 affect Deltaww Cncsoft?
CVE-2018-10598 affects Deltaww Cncsoft version 1.00.83 and prior, potentially allowing an attacker to gain remote code execution with administrator privileges.
How does CVE-2018-10598 affect Deltaww Screeneditor?
CVE-2018-10598 affects Deltaww Screeneditor version 1.00.54, potentially allowing an attacker to gain remote code execution with administrator privileges.
How can I mitigate CVE-2018-10598?
To mitigate CVE-2018-10598, it is recommended to update CNCSoft to a version later than 1.00.83 and ScreenEditor to a version later than 1.00.54, as they contain the necessary user input validation to prevent crashing and remote code execution.