#VU19527 Stack-based buffer overflow in EnergyPlus - CVE-2019-10974
Published: July 29, 2019 / Updated: July 29, 2019
EnergyPlus
National Renewable Energy Laboratory (NREL)
Description
The vulnerability allows a local attacker to escalate privileges on the system.
The vulnerability exists due to the application fails to prevent an exception handler from being overwritten with arbitrary code. A local authenticated attacker can trigger stack-based buffer overflow and execute arbitrary code on the target system or cause a denial-of-service condition.