Unrated severityNVD Advisory· Published Dec 31, 2020· Updated Sep 16, 2024
CHANGING Inc. NHIServiSignAdapter Windows Versions - Heap Overflow
CVE-2020-25843
Description
NHIServiSignAdapter fails to verify the length of digital credential files’ path which leads to a heap overflow loophole. Remote attackers can use the leak to execute code without privilege.
Affected products
1- Range: 1.0.20.0218
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.twcert.org.tw/tw/cp-132-4271-951cd-1.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.