ZeroHour

CVE-2018-7502

CVSS 3.0
7.8 high
EPSS
<1%p45
Published
()
Modified
Description

Kernel drivers in Beckhoff TwinCAT 3.1 Build 4022.4, TwinCAT 2.11 R3 2259, and TwinCAT 3.1 lack proper validation of user-supplied pointer values. An attacker who is able to execute code on the target may be able to exploit this vulnerability to obtain SYSTEM privileges.

Vendors
beckhoff
Products
twincat, twincat c\+\+
Weakness
CWE-822, CWE-20
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.