First published: Wed Mar 03 2021(Updated: )
A use after free issue has been identified in Fatek FvDesigner Version 1.5.76 and prior in the way the application processes project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Fatek FvDesigner | <=1.5.76 | |
FATEK Automation FvDesigner Version 1.5.76 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22662 has been classified as a critical vulnerability due to its potential for arbitrary code execution.
To mitigate CVE-2021-22662, it is recommended to upgrade Fatek FvDesigner to a version later than 1.5.76.
CVE-2021-22662 affects Fatek FvDesigner Version 1.5.76 and prior.
CVE-2021-22662 is a use after free vulnerability related to how project files are processed.
Yes, CVE-2021-22662 can allow an attacker to execute arbitrary code through a specially crafted project file.