Rewterz

Rewterz Threat Alert – CVE-2019-13518 – EZAutomation EZ Touch Editor Privilege Access Vulnerability

September 4, 2019
Rewterz

Rewterz Threat Alert – Malspam Campaign Distributing Remcos RAT using Password-protected Word docs

September 4, 2019

Rewterz Threat Alert – CVE-2019-13522 – EZAutomation EZ PLC Editor Code Execution Vulnerability

Severity

Medium

Analysis Summary

An attacker could use a specially crafted project file to corrupt the memory and execute code under the privileges of the application.

Impact

Improper Restriction of Operations within the Bounds of a Memory Buffer

Affected Vendors

EZAutomation

Affected Products

EZ PLC Editor Versions 1.8.41 and prior

Remediation

EZAutomation recommends users update to Version 1.9.0 or later

update to Version 1.9.0 or later

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.