Impact
Wind River VxWorks 7 software prior to build 26.09 has a flaw where certain system call arguments can trigger memory corruption within the memory management subsystem. This flaw falls under CWE‑787 and, if successfully exploited, could allow an attacker to alter memory contents, potentially leading to arbitrary code execution, privilege escalation, or denial of service for the affected system.
Affected Systems
Wind River VxWorks 7 on all versions before 26.09. Any deployment of VxWorks 7 running a pre‑26.09 build is susceptible.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score is not provided, so the exploitation probability is unknown, but the flaw was not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves privileged system calls; an attacker who controls such calls through local or remote interfaces could trigger the memory corruption. The vendor released a fix in 26.09, so systems remain at risk until upgraded.
OpenCVE Enrichment