CVE-2025-47756

Severity CVSS v4.0:
HIGH
Type:
CWE-125 Out-of-bounds Read
Publication date:
19/05/2025
Last modified:
19/05/2025

Description

V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!CGamenDataRom::set_mr400_strc function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fujielectric:monitouch_v-sft:*:*:*:*:*:*:*:* 6.0.1.0 (including) 6.2.6.0 (excluding)