CVE-2020-16217

7.8
7.8 / 10
HIGH

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. A double free vulnerability caused by processing specially crafted project files may allow remote code execution, disclosure/modification of information, or cause the application to crash.

Weakness: Double Free

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Published: 2020-08-06

Researcher Credit

Vulnerable Products

Community Advisory

This section is open source, for any additional information that enhances or clarifies the official advisory above.

Improve Advisory

CVE-2020-16217 Exploits

Exploits for CVE-2020-16217 are not publicly available.

Access our inventory of exclusive N-Day CVE Exploits, provided for legal security research and testing purposes. Inquire about our offerings by email: [email protected] (PGP key).

Official CVE References

View references (2)