Delta Electronics CNCSoft-G2 Version 2.1.0.16 and prior...
High severity
Unreviewed
Published
Mar 13, 2025
to the GitHub Advisory Database
•
Updated Mar 13, 2025
Description
Published by the National Vulnerability Database
Mar 13, 2025
Published to the GitHub Advisory Database
Mar 13, 2025
Last updated
Mar 13, 2025
Delta Electronics CNCSoft-G2 Version 2.1.0.16 and prior lacks proper
validation of the length of user-supplied data prior to copying it to a
fixed-length heap-based buffer. If a target visits a malicious page or
opens a malicious file an attacker can leverage this vulnerability to
execute code in the context of the current process.
References