CVE-2025-47749CWE-761

V-SFT v6.2.5.0 and earlier contains an issue with free of pointer not at start of buffer in VS6EditData.dll!CWinFontInf::WinFontMsgCheck function

High · published May 19, 2025

CVSS v4.0
8.4
EPSS
0%
Percentile
12.7
In the wild
Unconfirmed
What it is

V-SFT v6.2.5.0 and earlier contains an issue with free of pointer not at start of buffer in VS6EditData.dll!CWinFontInf::WinFontMsgCheck function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.

The record
Technical detail
CVSS v4.0
8.4 · HIGH
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00222 · 12.7th percentile
Weakness
CWE-761 · Free of Pointer not at Start of Buffer
Published
2025-05-19T07:43Z
EPSS history
Timeline
  • 19 MAY 07:43Z
    V-SFT v6.2.5.0 and earlier contains an issue with free of pointer not at start of buffer in VS6EditData.dll!CWinFontInf::WinFontMsgCheck function
    cvelistv5