A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.se.com/ww/en/download/document/SEVD-2020-315-03/ | vendor advisory |
https://www.zerodayinitiative.com/advisories/ZDI-21-095/ | vdb entry third party advisory |