Intrusion Prevention

Red.Lion.Crimson.CD3.ItemIndexList.Type.Confusion

Description

This indicates an attack attempt to exploit a Memory Corruption Vulnerability in Red Lion Crimson.
The vulnerability is due to an error when the vulnerable software handles a maliciously crafted CD3 file. A remote attacker can exploit this vulnerability by enticing a target user into opening a crafted CD3 file. Successful exploitation could result in the execution of arbitrary code as the user running Crimson.

Affected Products

Red Lion Crimson 3.0
Red Lion Crimson 3.1 prior to 3112.00

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Apply the most recent upgrade or patch from the vendor.
https://support.redlion.net/hc/en-us/articles/360033077531

CVE References

CVE-2019-10984

Other References

ICSA-19-248-01