This vulnerability allows remote attackers to execute arbitrary code on affected installations of Eaton EASYsoft. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of E70 files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software | Affected Version | How to fix |
---|---|---|
Eaton ELCSoft |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
ZDI-20-1442 has a critical severity level due to its potential for remote code execution.
To mitigate the ZDI-20-1442 vulnerability, users should update Eaton EASYsoft to the latest version provided by the vendor.
Only users of Eaton EASYsoft are affected by the ZDI-20-1442 vulnerability.
ZDI-20-1442 is a remote code execution vulnerability requiring user interaction.
If you have ZDI-20-1442, ensure to avoid visiting malicious sites and open files only from trusted sources until a fix is applied.