A CWE-125 Out-of-bounds Read vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.se.com/ww/en/download/document/SEVD-2020-315-03/ | vendor advisory |
https://www.zerodayinitiative.com/advisories/ZDI-21-096/ | vdb entry third party advisory |