CVE-2018-10636
Last modified
CVE-2018-10636 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has multiple stack-based buffer overflow vulnerabilities that could cause the software to crash due to lacking user input validation before copying data from project files onto the stack. Which may allow an attacker to gain remote code execution with administrator privileges if exploited.. EPSS estimates a 9.54% chance of exploitation in the next 30 days.
Description
CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has multiple stack-based buffer overflow vulnerabilities that could cause the software to crash due to lacking user input validation before copying data from project files onto the stack. Which may allow an attacker to gain remote code execution with administrator privileges if exploited.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Deltaww | Cncsoft | <= 1.00.83 |
| Deltaww | Screeneditor | 1.00.54 |
References
- http://www.securityfocus.com/bid/105032Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-219-01Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/105032Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-219-01Mitigation, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10636?
How severe is CVE-2018-10636?
How do I fix CVE-2018-10636?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-10630For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3…
- CVE-2018-10631The 8840 Clinician Programmer executes the application progr…6.3
- CVE-2018-10632In Moxa NPort 5210, 5230, and 5232 versions 2.9 build 170307…
- CVE-2018-10633Universal Robots Robot Controllers Version CB 3.1, SW Versio…
- CVE-2018-10634Communications between Medtronic MiniMed MMT pumps and wirel…4.8
- CVE-2018-10635In Universal Robots Robot Controllers Version CB 3.1, SW Ver…
- CVE-2018-10637A maliciously crafted project file may cause a buffer overfl…
- CVE-2018-1064libvirt version before 4.2.0-rc1 is vulnerable to a resource…
- CVE-2018-10641D-Link DIR-601 A1 1.02NA devices do not require the old pass…
- CVE-2018-10642Command injection vulnerability in Combodo iTop 2.4.1 allows…
- CVE-2018-10645Golden Frog VyprVPN 2.12.1.8015 for Windows suffers from a S…
- CVE-2018-10646CyberGhost 6.5.0.3180 for Windows suffers from a SYSTEM priv…
Are you affected by CVE-2018-10636?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
