CVE-2022-27648 is a critical stack-based buffer overflow vulnerability affecting KOYO Screen Creator 0.1.1.1, specifically within its parsing of SCA2 files. An attacker can exploit this by tricking a user into opening a malicious file or visiting a malicious page, leading to arbitrary code execution in the context of the current process. This vulnerability is rated High severity with a CVSS score of 7.8, indicating a local attack vector with low complexity but requiring user interaction, resulting in high impact to confidentiality, integrity, and availability. Currently, there is no known active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.1.1.4CPE matchmatch criteria | cpe:2.3:a:jtekt:screen_creator_advance_2:*:*:*:*:*:*:*:* | ||
0.1.1.4CPE matchmatch criteria | cpe:2.3:a:jtekt:screen_creator_advance_2:0.1.1.4:-:*:*:*:*:*:* | ||
0.1.1.4CPE matchmatch criteria | cpe:2.3:a:jtekt:screen_creator_advance_2:0.1.1.4:build01:*:*:*:*:*:* | ||
0.1.1.4CPE matchmatch criteria | cpe:2.3:a:jtekt:screen_creator_advance_2:0.1.1.4:build01b:*:*:*:*:*:* | ||
0.1.1.4CPE matchmatch criteria | cpe:2.3:a:jtekt:screen_creator_advance_2:0.1.1.4:build02:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.