Proface GP-Pro EX Stack Buffer Overflow Remote Code Execution Vulnerability
Proface GP-Pro EX Stack Buffer Overflow Remote Code Execution Vulnerability
Release date:
Updated on:
Affected Systems:
Proface GP-Pro EX
Description:
Proface GP-Pro EX is a human-machine interface HMI software used on multiple platforms.
Proface GP-Pro EX has a security vulnerability in BeginPreRead processing. When handling malformed 0x7 f77 fields, attackers can exploit this vulnerability to cause stack buffer overflow and execute arbitrary code in the context of the current process.
<* Source: Steven Seeley (seeleymagic@hotmail.com)
Link: http://www.zerodayinitiative.com/advisories/ZDI-16-003/
*>
Suggestion:
Vendor patch:
Proface
-------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.profaceamerica.com/en-US/content/gp-pro-ex-hmi-software
This article permanently updates the link address: