Panasonic FPWIN Pro version 7.3.0.0 and prior allows attacker-created project files to be loaded by an authenticated user triggering incompatible type errors because the resource does not have expected properties. This may lead to remote code execution.
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
Link | Tags |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-19-157-02 | us government resource mailing list patch third party advisory |
http://www.securityfocus.com/bid/108683 | vdb entry third party advisory |
https://www.zerodayinitiative.com/advisories/ZDI-19-568/ | vdb entry third party advisory |
https://www.zerodayinitiative.com/advisories/ZDI-19-566/ | vdb entry third party advisory |
https://www.zerodayinitiative.com/advisories/ZDI-19-570/ | vdb entry third party advisory |