First published: Wed Aug 08 2018(Updated: )
CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has two out-of-bounds read vulnerabilities could cause the software to crash due to lacking user input validation for processing project files. Which may allow an attacker to gain remote code execution with administrator privileges if exploited.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Cncsoft | <=1.00.83 | |
Deltaww Screeneditor | =1.00.54 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10598 is a vulnerability in CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 that allows an attacker to gain remote code execution with administrator privileges.
The severity of CVE-2018-10598 is high, with a CVSS score of 8.1.
CVE-2018-10598 affects Deltaww Cncsoft version 1.00.83 and prior, potentially allowing an attacker to gain remote code execution with administrator privileges.
CVE-2018-10598 affects Deltaww Screeneditor version 1.00.54, potentially allowing an attacker to gain remote code execution with administrator privileges.
To mitigate CVE-2018-10598, it is recommended to update CNCSoft to a version later than 1.00.83 and ScreenEditor to a version later than 1.00.54, as they contain the necessary user input validation to prevent crashing and remote code execution.