CVE-2018-7817
Description
A use-after-free vulnerability in Zelio Soft 2 prior to v5.2 allows remote code execution when opening a specially crafted project file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A use-after-free vulnerability in Zelio Soft 2 prior to v5.2 allows remote code execution when opening a specially crafted project file.
Vulnerability
A Use After Free (CWE-416) vulnerability exists in Zelio Soft 2 version 5.1 and prior versions [1]. This occurs when the software processes a specially crafted project file, as the programming platform fails to properly manage memory after it has been freed, leading to potential exploitation [1].
Exploitation
Exploitation requires low skill level and user interaction [1]. An attacker must convince a user to open a maliciously crafted Zelio Soft project file [1]. The attack vector is local, meaning the attacker needs to deliver the file to the target system, but no special privileges are required by the attacker prior to the exploit [1].
Impact
Successful exploitation results in remote code execution in the context of the application [1]. The CVSS v3 base score of 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates a high impact on confidentiality, integrity, and availability, though the scope remains unchanged [1].
Mitigation
Schneider Electric has released version 5.2 of Zelio Soft to fix this vulnerability [1]. Users should upgrade to the latest version available for download. Additionally, CISA recommends minimizing network exposure for control system devices, locating them behind firewalls, and using secure remote access methods [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=5.1
- Schneider Electric SE/Zelio Soft 2 v5.1 and prior versionsv5Range: Zelio Soft 2 v5.1 and prior versions
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
3- www.securityfocus.com/bid/106481mitrevdb-entryx_refsource_BID
- ics-cert.us-cert.gov/advisories/ICSA-19-008-01mitrex_refsource_MISC
- www.schneider-electric.com/en/download/document/SEVD-2018-361-01/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.