V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds write in VS6EditData!CDataRomErrorCheck::MacroCommandCheck function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://monitouch.fujielectric.com/site/download-e/09vsft6_inf/Search.php | release notes vendor advisory |
https://jvn.jp/en/vu/JVNVU97228144/ | third party advisory |