Delta Electronics CNCSoft-G2 File Parsing Memory Corruption Vulnerability Allowing Code Execution

Vulnerability

A memory corruption vulnerability due to improper validation of user-supplied files has been identified in Delta Electronics CNCSoft-G2, specifically in versions through 2.1.0.20. This vulnerability allows an attacker to execute code within the context of the current process by opening a malicious file.

Impact

Exploitation of this vulnerability leads to an out-of-bounds write, allowing for memory corruption and potential arbitrary code execution.

Remediation

Users are advised to download and update to CNCSoft-G2 version 2.1.0.27 or later.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
1.2
impact
7.5
exploitability
4.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.