VulnerabilityModified
CVE-2019-12551
In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the Memcpy function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution.
MEDIUM 5.5EPSS 2.14%
Does this matter?
Lower severity and a low EPSS score (2.14%). Track it; it rarely justifies an emergency change on its own.
Description
In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the Memcpy function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 2.14% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- sweetscape/010 editor
- Source
- cve@mitre.org
References
- https://ereisr00.github.io/Exploit, Third Party Advisory
- https://github.com/ereisr00/bagofbugz/blob/master/010EditorExploit, Third Party Advisory
- https://www.sweetscape.com/010editor/manual/ReleaseNotes.htmRelease Notes, Vendor Advisory
- https://ereisr00.github.io/Exploit, Third Party Advisory
- https://github.com/ereisr00/bagofbugz/blob/master/010EditorExploit, Third Party Advisory
- https://www.sweetscape.com/010editor/manual/ReleaseNotes.htmRelease Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.