#VU18984 Out-of-bounds write in WebAccess/SCADA - CVE-2019-10987
Published: July 3, 2019
WebAccess/SCADA
Advantech Co., Ltd
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing data passed to the webvrpcs process, within bwdraw.exe accessible through the 0x2711 IOCTL. A remote attacker can send a specially crafted file to the affected application, trigger out-of-bounds write error and execute arbitrary code on the system.