CVE-2019-12871
Description
A Use-After-Free vulnerability in PHOENIX CONTACT PC Worx, PC Worx Express, and Config+ allows remote code execution via a manipulated project file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A Use-After-Free vulnerability in PHOENIX CONTACT PC Worx, PC Worx Express, and Config+ allows remote code execution via a manipulated project file.
Vulnerability
A Use-After-Free vulnerability has been discovered in PHOENIX CONTACT PC Worx through version 1.86, PC Worx Express through version 1.86, and Config+ through version 1.86 [1]. The flaw exists within the parsing of BCP files, where the application fails to validate the existence of an object prior to performing operations on it [1]. The attacker must first obtain an original project file from the target workstation, manipulate it, and then replace the original file with the tampered one [1][2].
Exploitation
Exploitation requires user interaction, specifically the target user must open the malicious project file, either by visiting a malicious page or opening the manipulated file directly [1]. The attacker needs local access to the application programming workstation to exchange the original file with the modified one [1][2]. No authentication is needed to trigger the vulnerability once the user opens the file, and the attack vector is local, meaning the attacker must have some degree of access to the system or rely on social engineering [1].
Impact
Successful exploitation leads to remote code execution in the context of the current process [1]. The CVSS v3 base score is 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), indicating high impact on confidentiality, integrity, and availability [1]. The attacker effectively gains the ability to execute arbitrary code on the affected workstation.
Mitigation
As of the available references, no fixed version has been published. The vendor was notified and the vulnerability disclosed via ZDI in June 2019 [1]. Users should ensure that project files are obtained from trusted sources and avoid opening files from untrusted origins [1][2]. If a patch becomes available, it should be applied immediately. No workaround other than cautious file handling is documented.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- PHOENIX CONTACT/PC Worxdescription
- Range: <=1.86
- Range: <=1.86
- Range: <=1.86
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- cert.vde.com/en-us/advisories/vde-2019-014mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-19-578/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.