|CVSS SCORE||9.3, (AV:N/AC:M/Au:N/C:C/I:C/A:C)|
The specific flaw exists within the parsing of hsc files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code under the context of an administrator.
05/18/18 - ZDI sent the report to ICS-CERT
|CREDIT||Mat Powell - Trend Micro Zero Day Initiative