Description
A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an attacker to use the exp.adpx file as a zip compressed file to construct a special file name, which can be used to decompress the project file into the system startup folder, restart the system, and automatically execute the constructed attack script.
References (2)
Core 2
Core References
Third Party Advisory
https://gist.github.com/zty-1995/effed155177edd7b22fdf2c082e32984
Scores
CVSS v3
3.3
EPSS
0.0105
EPSS Percentile
77.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-22
Status
published
Products (1)
wondershare/edraw
3.2.2
Published
Oct 02, 2024
Tracked Since
Feb 18, 2026