ZDI-24-1166: Delta Electronics DIAScreen DPA File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DIAScreen. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-7502.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1166?
The severity of ZDI-24-1166 is high due to its potential for remote code execution.
How do I fix ZDI-24-1166?
To fix ZDI-24-1166, ensure that you update to the latest patched version of Delta Electronics DIAScreen.
What is the impact of ZDI-24-1166?
ZDI-24-1166 allows remote attackers to execute arbitrary code, leading to potential data breaches and system compromise.
Is user interaction required to exploit ZDI-24-1166?
Yes, user interaction is required for ZDI-24-1166 as it involves visiting a malicious page or opening a malicious file.
What versions of Delta Electronics DIAScreen are affected by ZDI-24-1166?
All installations of Delta Electronics DIAScreen are potentially affected by ZDI-24-1166 if they have not been updated.