CVE-2022-3379

EUVD-2022-42757
Horner Automation's Cscape version 9.90 SP7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by writing outside the memory buffer.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
icscertCNA
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
Affected Products (NVD)
VendorProductVersion
hornerautomationcscape
𝑥
< 9.90
hornerautomationcscape
9.90
hornerautomationcscape
9.90:sp1
hornerautomationcscape
9.90:sp2
hornerautomationcscape
9.90:sp3
hornerautomationcscape
9.90:sp4
hornerautomationcscape
9.90:sp5
hornerautomationcscape
9.90:sp6
hornerautomationcscape
9.90:sp7
𝑥
= Vulnerable software versions