CVE-2025-58319: File Parsing Memory Corruption in CNCSoft-G2
Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Delta Electronics CNCSoft-G2to a version that resolves this vulnerability.Fixed in v2.1.0.34
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58319?
CVE-2025-58319 is considered a critical vulnerability due to the risk of arbitrary code execution from opening malicious files.
How do I fix CVE-2025-58319?
To mitigate CVE-2025-58319, users should apply the latest security updates provided by Delta Electronics for CNCSoft-G2.
What systems are affected by CVE-2025-58319?
CVE-2025-58319 affects Delta Electronics CNCSoft-G2 software, which lacks proper validation of user-supplied files.
Can CVE-2025-58319 be exploited remotely?
Yes, CVE-2025-58319 can be exploited by an attacker if a user opens a specifically crafted malicious file.
What kind of attacks can CVE-2025-58319 enable?
CVE-2025-58319 can enable attackers to execute arbitrary code in the context of the current user process.