Stack-based buffer overflow in WECON LeviStudioU - CVE-2021-43983
Published: December 10, 2021 / Updated: January 17, 2022
WECON LeviStudioU
WECON Technology Co., Ltd.
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error while parsing project files. A remote unauthenticated attacker can trick the victim to open a specially crafted UMP file, trigger stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
External links
- https://ics-cert.us-cert.gov/advisories/icsa-21-343-02
- https://www.zerodayinitiative.com/advisories/ZDI-22-034/
- https://www.zerodayinitiative.com/advisories/ZDI-22-035/
- https://www.zerodayinitiative.com/advisories/ZDI-22-036/
- https://www.zerodayinitiative.com/advisories/ZDI-22-037/
- https://www.zerodayinitiative.com/advisories/ZDI-22-038/
- https://www.zerodayinitiative.com/advisories/ZDI-22-039/
- https://www.zerodayinitiative.com/advisories/ZDI-22-040/
- https://www.zerodayinitiative.com/advisories/ZDI-22-041/
- https://www.zerodayinitiative.com/advisories/ZDI-22-042/
- https://www.zerodayinitiative.com/advisories/ZDI-22-043/
- https://www.zerodayinitiative.com/advisories/ZDI-22-044/
- https://www.zerodayinitiative.com/advisories/ZDI-22-045/
- https://www.zerodayinitiative.com/advisories/ZDI-22-046/
- https://www.zerodayinitiative.com/advisories/ZDI-22-047/