CVE-2018-8835: Double Free
Double free vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-8835?
CVE-2018-8835 is a vulnerability in Advantech WebAccess HMI Designer that allows remote code execution.
What is the severity of CVE-2018-8835?
CVE-2018-8835 has a severity rating of 7.8, which is considered high.
How does CVE-2018-8835 occur?
CVE-2018-8835 occurs due to double free vulnerabilities in Advantech WebAccess HMI Designer when processing specially crafted .pm3 files.
How can I fix CVE-2018-8835?
To fix CVE-2018-8835, update Advantech WebAccess HMI Designer to version 2.1.7.33 or later.
Where can I find more information about CVE-2018-8835?
You can find more information about CVE-2018-8835 on the following websites: - [SecurityFocus](http://www.securityfocus.com/bid/103972) - [ICS-CERT](https://ics-cert.us-cert.gov/advisories/ICSA-18-114-03)