Type Confusion in Control FPWIN Pro - CVE-2019-6532
Published: June 19, 2019
Control FPWIN Pro
Detailed vulnerability description
The vulnerability allows a local attacker to execute arbitrary code on the target system.
The vulnerability exists due to a type confusion error within the parsing of PRO files. A local authenticated attacker can create project files, load them, trigger a type confusion error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.