Impact
This vulnerability is a classic use-after-free flaw found in the Security Plugins of RTI Connext Professional. The flaw permits an attacker who can trigger the freed memory to manipulate file contents, potentially overwriting or corrupting configuration or log files. The impact is data integrity violation and could lead to unauthorized changes or denial of service if critical files are corrupted.
Affected Systems
Affected versions are all releases from 7.6.0 up to but excluding 7.7.0.1 of RTI Connext Professional. Users running any of these builds must verify the installed version and plan an update. No other products or versions are affected according to the CNA data.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity, and the lack of an EPSS score means no recent exploitation data is available, though the vulnerability remains in the CWE-416 category. The vulnerability is not catalogued in CISA's KEV list. Based on the description, the likely attack vector is any component that interacts with the Security Plugins that could be supplied malicious data; thus an attacker may need code execution or local access to create the conditions for the use-after-free. In absence of exploitation evidence, administrators should treat it as a high-risk local vulnerability.
OpenCVE Enrichment