Impact
Integer overflow or wraparound in RTI Connext Professional core libraries permits an attacker to manipulate shared resources. The flaw arises when an attacker can supply control data that causes the library to incorrectly calculate addresses or indices, leading to unauthorized modifications or reads of data structures. This can result in privilege escalation within a shared process or denial of service if critical shared objects are corrupted. The weakness is identified as CWE‑190 and CWE‑284.
Affected Systems
RTI Connext Professional is impacted. Vulnerable releases include any from version 7.4.0 up to but not including 7.7.0.1, from 7.0.0 up to but not including 7.3.1.6, and all 6.1.0 releases prior to the last 6.1.*. Systems using these versions should verify their exact build and consider remediation.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.3, indicating high severity. EPSS is not reported, so recent exploitation probability cannot be quantified; however, the flaw involves an integer overflow that can be triggered in a shared context, implying that a remote or local attacker with access to the system could exploit it. The CVE is not listed in CISA KEV, but the high impact warrants precautionary measures.
OpenCVE Enrichment