Impact
The vulnerability exists in the SConnect native host component, where a combination of cryptographic weaknesses and memory management flaws can be abused to execute arbitrary code without authentication. This flaw allows an attacker to forge malicious input that bypasses security checks, leading to remote code execution on the victim machine. The weakness falls under several common weakness enumerations including lack of input validation (CWE‑130), improper authorization (CWE‑252), uninitialized memory usage (CWE‑347), and improper resource handling (CWE‑457). Consequently, an attacker who can reach the vulnerable messaging interface can run arbitrary code with the privileges of the native host process, potentially compromising the entire system.
Affected Systems
The affected software is Thales SConnect, a connectivity platform that facilitates secure messaging between web applications and native host components. Specific product versions are not listed in the advisory, but any installation of the SConnect native host component may be vulnerable.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity, and the lack of an available EPSS score prevents a precise exploitation probability estimate, but the absence of a known KEV listing does not diminish the risk. Based on the description, the likely attack vector is through an unrestricted messaging interface exposed to web content, allowing an attacker to craft messages from a malicious web page that interacts with the native host. Exploitation would require the victim to load or trust the attacker‑controlled page, and no prior authentication is needed. The exploit is therefore potentially exploitable from any external source that can trigger the messaging interface.
OpenCVE Enrichment