Impact
The flaw allows an attacker to extract a compromised CMSIS‑Pack archive in Eclipse Embedded CDT versions 6.0–6.7 to write arbitrary files outside the intended extraction directory. This arbitrary file write (CWE-22) could overwrite critical system or IDE files, inject malicious binaries, or modify build configurations, exposing the system to potential code execution or data exfiltration. The vulnerability arises from insufficient path validation during archive extraction.
Affected Systems
Eclipse Foundation’s Eclipse Embedded CDT (C/C++ Development Tools) is affected. Versions 6.0 through 6.7 contain the flaw, allowing the extraction of CMSIS‑Pack archives to write files outside the intended workspace directory. The vulnerability is not listed in CISA KEV.
Risk and Exploitability
EPSS score is not available and the issue is not listed in CISA KEV. While public exploit data is lacking, the write capability presents a serious risk. Exploitation would require the attacker to supply a malicious CMSIS‑Pack and trigger its extraction within the IDE, typically a local or privileged user scenario, but could be abused by remote users if they can gain IDE access.
OpenCVE Enrichment