VYPR
Unrated severityNVD Advisory· Published Sep 26, 2019· Updated Aug 5, 2024

CVE-2019-16901

CVE-2019-16901

Description

Advantech WebAccess/HMI Designer 2.1.9.31 has Exception Handler Chain corruption starting at Unknown Symbol @ 0x0000000000000000 called from ntdll!RtlRaiseStatus+0x00000000000000b4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Advantech WebAccess/HMI Designer 2.1.9.32 (or earlier) has an exception handler chain corruption leading to a crash.

Vulnerability

Advantech WebAccess/HMI Designer version 2.1.9.31 (and possibly earlier versions) contains an exception handler chain corruption vulnerability. The issue manifests as a crash starting at ntdll!RtlRaiseStatus+0x00000000000000b4 with an unknown symbol at address 0x0000000000000000. The crash is triggered via fuzzing, indicating that the application does not properly handle malformed input, leading to corruption of the exception handling structures. The affected version is explicitly 2.1.9.31 as tested in the reference [1].

Exploitation

An attacker with local access to the system where WebAccess/HMI Designer is installed can cause the application to crash by providing specially crafted input (e.g., via a malformed project file or network data). The fuzzing approach in the reference [1] suggests that the vulnerability is reachable through the UI or file parsing functionality. No authentication or special privileges are required beyond the ability to interact with the application. The attack does not require user interaction beyond opening the malformed file or data.

Impact

Successful exploitation leads to a denial-of-service condition as the application crashes. The provided details do not indicate arbitrary code execution or privilege escalation. The crash is reproducible and results in an application termination, potentially causing loss of unsaved work and disruption of service.

Mitigation

As of the publication date (2019-09-26), no official patch or fixed version has been released. The vendor (Advantech) may have provided an update in a later version beyond 2.1.9.31. Users should check for the latest version of WebAccess/HMI Designer and apply any available updates. Until a fix is available, avoid opening untrusted files or data in the application to reduce the risk of exploitation.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.