Impact
An out-of-bounds write in AutomationDirect's Productivity Suite allows a local attacker to send a crafted IOCTL request that corrupts kernel memory. This compromise can lead to privilege escalation, allowing the attacker to gain higher system rights, or cause system instability through memory corruption, potentially resulting in crashes or unexpected behavior.
Affected Systems
The vulnerable component is the Productivity Suite distributed by AutomationDirect. Versions prior to 4.7.0.47 are affected; the vendor recommends upgrading to 4.7.0.47 or newer. The flaw exists in the core of the suite, so any installation that accepts local IOCTL communication is susceptible.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity, though the EPSS score of < 1% suggests a low overall probability of exploitation in the wild. The vulnerability is local in nature, requiring an attacker with physical or network access to the device to trigger the IOCTL request. It is not currently listed in the CISA KEV catalog, so no known active exploits have been reported yet.
OpenCVE Enrichment