VYPR
Critical severity9.8NVD Advisory· Published Sep 5, 2018· Updated Jun 17, 2026

CVE-2018-16518

CVE-2018-16518

Description

A directory traversal vulnerability with remote code execution in Prim'X Zed! FREE through 1.0 build 186 and Zed! Limited Edition through 6.1 build 2208 allows creation of arbitrary files on a user's workstation using crafted ZED! containers because the watermark loading function can place an executable file into a Startup folder.

Affected products

4
  • PRIMX/Zed\! Freellm-create2 versions
    <=1.0 build 186+ 1 more
    • (no CPE)range: <=1.0 build 186
    • cpe:2.3:a:primx:zed\!_free:*:*:*:*:*:*:*:*range: <=1.0
  • Range: <=6.1 build 2208
  • cpe:2.3:a:primx:zed\!:*:*:*:*:*:*:*:*
    Range: <=6.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.