Executive brief
Schneider Electric IGSS is an industrial control system software used to monitor and manage automated processes. A security flaw in the IGSS Definition component allows an attacker to compromise the system if a user is tricked into importing a specially crafted configuration file. Successful exploitation could lead to a complete loss of system control, data theft, or the execution of unauthorized commands on the workstation.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the IGSS Definition component (Def.exe) of Schneider Electric IGSS. The flaw is triggered during the import of a malicious CGF (Configuration) file. An attacker can exploit this by crafting a file that causes the application to write data beyond the boundaries of allocated memory buffers. This requires local access to the system and user interaction to initiate the import process. Successful exploitation can result in memory corruption, leading to a denial-of-service condition or arbitrary code execution with the privileges of the application.
Affected products
- Schneider Electric IGSS Definition (Def.exe) Version 18.0.0.26124 and prior
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory