#VU85430 Deserialization of Untrusted Data in Easergy Studio - CVE-2023-7032
Published: January 16, 2024 / Updated: February 12, 2024
Easergy Studio
Schneider Electric
Description
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data. A local user can pass specially crafted data to the application and execute arbitrary code on the target system with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.