#VU109670 Free of Pointer not at Start of Buffer in Monitouch V-SFT - CVE-2025-47749
Published: May 23, 2025
Monitouch V-SFT
Fuji Electric
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to free of pointer not at start of buffer in "VS6EditData.dll!CWinFontInf::WinFontMsgCheck" function. A remote attacker can trick a victim to open a specially crafted V7 or V8 file and execute arbitrary code on the target system.