CVE-2026-11389
6.8RTI · Connext Professional
RTI Connext Professional contains multiple memory safety vulnerabilities, including out-of-bounds read and type confusion, allowing for potential buffer overreads in the Core Libraries.
Executive summary
A series of memory safety vulnerabilities in RTI Connext Professional allows local attackers with low privileges to trigger buffer overreads, potentially leading to a denial of service.
Vulnerability
This vulnerability involves out-of-bounds read (CWE-125), incorrect function argument counts (CWE-685), and type confusion (CWE-843) flaws within the Core Libraries. A locally authenticated user with low privileges can trigger these conditions to cause memory errors.
Business impact
The exploitation of these flaws poses a risk to system stability, as they allow for buffer overreads that may result in application crashes or denial of service. While the CVSS score of 6.8 reflects a medium severity, the impact on availability is high, which could disrupt critical industrial or messaging communications handled by Connext Professional.
Remediation
Immediate Action: Update RTI Connext Professional to version 7.7.0.1 or 7.3.1.6 as directed by the vendor security advisory.
Proactive Monitoring: Monitor system and application logs for unusual crash reports or diagnostic events associated with the Core Libraries.
Compensating Controls: Restrict local system access to authorized personnel only to mitigate the risk posed by the requirement for local, low-privileged access.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing RTI Connext Professional should prioritize the transition to the patched versions (7.7.0.1 or 7.3.1.6). Given the nature of these vulnerabilities in core messaging libraries, ensuring the integrity of the runtime environment is essential to preventing potential service interruptions.
More RTI CVEs
History
- Analyst report written