VYPR
Unrated severityNVD Advisory· Published Sep 26, 2019· Updated Aug 5, 2024

CVE-2019-16900

CVE-2019-16900

Description

Advantech WebAccess/HMI Designer 2.1.9.31 has a User Mode Write AV starting at MSVCR90!memcpy+0x000000000000015c.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Advantech WebAccess/HMI Designer 2.1.9.31 has a user-mode write access violation in MSVCR90!memcpy, potentially leading to denial of service or code execution.

Vulnerability

Advantech WebAccess/HMI Designer version 2.1.9.31 contains a user-mode write access violation in the memcpy function of MSVCR90.dll at offset 0x15c. The crash occurs when the application processes malformed data, likely from a specially crafted project file or network input. The vulnerability was identified through fuzzing [1].

Exploitation

An attacker can trigger the vulnerability by convincing a user to open a malicious file (e.g., via email or download) with the HMI Designer application. No authentication is required. The crash results from a write to an invalid memory address controlled by the attacker, potentially allowing for arbitrary write if the address is controllable.

Impact

Successful exploitation could cause a denial of service (application crash) or, if the write destination is controlled, arbitrary code execution in the context of the current user. The exact impact depends on memory layout and exploitability.

Mitigation

As of the publication date (2019-09-26), no official patch or advisory from Advantech has been released. Users should avoid opening untrusted files and consider restricting execution of the HMI Designer application. Monitor Advantech's support portal for future updates.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.