#VU13927 Stack-based buffer overflow in InTouch - CVE-2018-10628
Published: July 19, 2018 / Updated: July 20, 2018
InTouch
AVEVA Software, LLC.
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to stack-based buffer overflow on a locale not using a dot floating point separator. A remote unauthenticated attacker can send a specially crafted packet, trigger memory corruption and execute arbitrary code under the privileges of the InTouch View process.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.