CVE-2020-16199: Delta Industrial Automation CNCSoft ScreenEditor DPB File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Industrial Automation CNCSoft ScreenEditor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DPB files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of Administrator.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-16199?
CVE-2020-16199 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Delta Industrial Automation CNCSoft ScreenEditor.
How does CVE-2020-16199 impact Delta Industrial Automation CNCSoft ScreenEditor?
CVE-2020-16199 allows remote attackers to execute arbitrary code on affected installations of Delta Industrial Automation CNCSoft ScreenEditor.
What is the severity of CVE-2020-16199?
The severity of CVE-2020-16199 is high with a CVSS score of 7.8.
How can CVE-2020-16199 be exploited?
To exploit CVE-2020-16199, user interaction is required, such as visiting a malicious page or opening a malicious file.
How can I protect my Delta Industrial Automation CNCSoft ScreenEditor installation from CVE-2020-16199?
To protect your Delta Industrial Automation CNCSoft ScreenEditor installation from CVE-2020-16199, ensure you update to a version higher than 1.01.23.