CVE-2019-10961
Description
In Advantech WebAccess HMI Designer Version 2.1.9.23 and prior, processing specially crafted MCR files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, allowing remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Advantech WebAccess HMI Designer versions ≤2.1.9.23 contain an out-of-bounds write in MCR file parsing, enabling remote code execution via a crafted file.
Vulnerability
Advantech WebAccess HMI Designer versions 2.1.9.23 and prior contain an out-of-bounds write vulnerability during the processing of specially crafted MCR files. The issue stems from a lack of proper validation of user-supplied data, resulting in a write past the end of an allocated buffer [1][2]. This flaw exists in the application's handling of MCR files, a human-machine interface development file format.
Exploitation
An attacker can exploit this vulnerability by convincing a user to open a malicious MCR file, for example via a web link or email attachment. No authentication is required, but user interaction is necessary. The attacker crafts an MCR file that triggers the out-of-bounds write when processed by the affected software. The CVSS vector indicates local access (AV:L) and low complexity [1][2].
Impact
Successful exploitation allows an attacker to execute arbitrary code in the context of the current process, achieving full compromise of confidentiality, integrity, and availability of the affected system. The attacker can gain the same privileges as the user running the HMI Designer [1][2].
Mitigation
Advantech released version 2.1.9.31 of WebAccess HMI Designer to address this vulnerability. Users are advised to update immediately. As a workaround, users should exercise caution when opening MCR files from untrusted sources and avoid clicking unsolicited links or attachments [2]. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog at the time of publication.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Advantech/WebAccess HMI Designerdescription
- Range: <=2.1.9.23
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.us-cert.gov/ics/advisories/icsa-19-213-01mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-19-691/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.