Published:2024/03/29  Last Updated:2024/03/29

JVNVU#95439120
Multiple vulnerabilities in KEYENCE KV STUDIO and KV REPLAY VIEWER

Overview

KV STUDIO and KV REPLAY VIEWER provided by KEYENCE CORPORATION contain multiple vulnerabilities.

Products Affected

  • KV STUDIO
    • Ver.11.64 and earlier
  • KV REPLAY VIEWER
    • Ver.2.64 and earlier

Description

KV STUDIO and KV REPLAY VIEWER provided by KEYENCE CORPORATION contain multiple vulnerabilities listed below.

  • Out-of-bounds write (CWE-787) - CVE-2024-29218
    CVSS v3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Base Score: 7.8
  • Out-of-bounds read (CWE-125) - CVE-2024-29219
    CVSS v3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Base Score: 7.8

Impact

Information may be disclosed or arbitrary code may be executed by having a user of the affected product open a specially crafted file.

Solution

Update the software
Update the software to the latest version according to the information provided by the developer.

Vendor Status

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Michael Heinzl reported these vulnerabilities to JPCERT/CC.
JPCERT/CC coordinated with the developer.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2024-29218
CVE-2024-29219
JVN iPedia