Executive brief
RTI Connext Professional is middleware that enables real-time data sharing between distributed applications in automotive, industrial, and financial systems. A format string vulnerability in its Core Libraries could allow an attacker to read memory, crash the application, or potentially execute code if they can inject malicious format strings into the system. Organizations using affected versions should apply the security patches released by RTI.
Technical details
The Core Libraries component in RTI Connext Professional contains a use of externally-controlled format string vulnerability that enables format string injection attacks. An attacker with network access or local access to the system can inject format strings to read or write memory, leading to information disclosure or denial of service. RTI has released patches for affected versions (7.7.0.1 and later for the 7.5.x branch, 7.3.1.6 and later for the 7.3.x branch).
Affected products
- RTI Connext Professional 7.5.0 to 7.7.0.0, 7.3.0.10 to 7.3.1.5
Timeline
- 2026-09-22: disclosed