Impact
The vulnerability is a format string injection that permits an attacker to control the format string used by the application’s core libraries. If exploited, the attacker can cause the application to interpret the string as a format specifier, potentially leading to arbitrary code execution or memory disclosure.
Affected Systems
RTI Connext Professional, Core Libraries. Affected versions include all releases from 7.5.0 up to, but not including, 7.7.0.1 and from 7.3.0.10 up to, but not including, 7.3.1.6.
Risk and Exploitability
The CVSS score of 9.2 indicates a critical severity. The EPSS score is not available, so the current exploitation probability is uncertain, though a lack of KEV listing means no known exploit has been reported yet. Based on the description, it is inferred that the attack could originate from any interface that accepts user‑controlled input to formatting functions, which may include networked API callers or local debug functions. The high severity combined with the absence of an existing exploit suggests that organizations should consider this a high priority for patching or mitigation.
OpenCVE Enrichment