Executive brief
RTI Connext Professional is middleware that enables real-time data distribution in industrial and enterprise systems. A type confusion vulnerability in the Core Libraries could allow an attacker to read memory beyond buffer boundaries, potentially exposing sensitive data or causing system crashes in applications that depend on Connext for critical communication.
Technical details
The vulnerability involves an out-of-bounds read combined with type confusion in the Core Libraries, allowing an attacker to access memory using an incompatible type. The precise attack vector and preconditions are not detailed in available references, but the issue affects multiple version lines of Connext Professional and can result in buffer overreads that expose internal state or corrupt execution flow.
Affected products
- RTI Connext Professional 7.4.0 before 7.7.0.1, 7.3.0 before 7.3.1.6, 6.1.2.21 and later before 6.1.x end of support
Timeline
- 2026-09-22: disclosed