Impact
The vulnerability is a stack-based buffer overflow caused by missing hardening protections in the BigFix Quantum Risk Analyzer binary. An attacker may trigger the overflow by feeding crafted input or otherwise manipulating execution flow, potentially leading to non‑privileged code execution within the context of the running process. The flaw is identified as CWE‑121 and presently carries a CVSS score of 3.9, indicating low overall severity but still representing a code‑execution risk.
Affected Systems
Affected product is HCL Software’s BigFix Quantum Risk Analyzer. The specific versions impacted are not enumerated in the available data; it applies to the binary supplied by HCL under current releases that lack industry‑standard hardening. Administrators should verify the version of the installed bundle against HCL documentation for exposed builds.
Risk and Exploitability
Given its CVSS rating of 3.9, the risk is considered low from an exploitability standpoint. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Because the application is a desktop binary, the likely attack vector is local execution, but a malicious actor could potentially exploit it from a compromised network if the binary is callable remotely. No published remote exploitation evidence is known at this time.
OpenCVE Enrichment