Impact
The flaw allows an attacker to extract a compromised CMSIS‑Pack archive in Eclipse Embedded CDT versions 6.0–6.7 to write arbitrary files outside the intended extraction directory. This arbitrary file write (CWE-22) could overwrite critical system or IDE files, inject malicious binaries, or modify build configurations, exposing the system to potential code execution or data exfiltration. The vulnerability arises from insufficient path validation during archive extraction.
Affected Systems
Eclipse Foundation’s Eclipse Embedded CDT (6.0 through 6.7 contain the flaw, allowing the extraction of CMSIS‑Pack archives to write files outside the intended workspace directory. The vulnerability is not listed in CISA KEV.
Risk and Exploitability
The EPSS score of <1% indicates a low but non‑zero likelihood of exploitation, and the CVSS base score is 9.1, reflecting high severity due to arbitrary file write. While no public exploits are documented, the vulnerability allows an attacker who supplies a malicious CMSIS‑Pack and triggers its extraction within the IDE to overwrite files outside the intended directory. This capability can potentially replace critical workspace or system files, leading to code execution or data compromise. Based on the description, it is inferred that the likely attack vector involves local or privileged access to the IDE to trigger extraction, but a remote attacker might leverage the vulnerability if they can gain IDE access. Thus the risk depends on user privileges and access method.
OpenCVE Enrichment