#VU16649 Improper input validation in Cscape - CVE-2018-19005
Published: December 20, 2018 / Updated: December 21, 2018
Cscape
Horner Automation
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to an error when processing malicious input. A remote attacker can trick the victim into opening a specially crafted POC files to read confidential information and remotely execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.