← Vulnerability feed

Vulnerability record · CVE-2022-26507 · published 14 April 2022

CVE-2022-26507: Att xmill out-of-bounds write vulnerability

Att · Xmill

A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or CVE-2021-21830. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

9.8 CVSS 3.1 Critical EPSS 2.4% · top 16.5% CWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score, v2 7.5
2.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or CVE-2021-21830. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://Claroty.com Not ApplicableThird Party Advisory
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-222-02 MitigationRelease NotesThird Party Advisory
https://Claroty.com Not ApplicableThird Party Advisory
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-222-02 MitigationRelease NotesThird Party Advisory

Track CVE-2022-26507 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-45789Schneider-electric ecostruxure control expert authentication bypass by capture-replay vulnerabilityA CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller…EPSS 1.5%9.8CVE-2022-45788Schneider-electric ecostruxure control expert vulnerabilityA CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and…EPSS 1.2%9.8CVE-2022-37300Schneider-electric ecostruxure control expert weak password recovery vulnerabilityA CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode t…EPSS 0.75%9.8CVE-2021-21811Att xmill vulnerabilityA memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file c…EPSS 1.1%9.8CVE-2021-21826Att xmill classic buffer overflow vulnerabilityA heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBl…EPSS 1.1%9.8CVE-2021-21827Att xmill classic buffer overflow vulnerabilityA heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBl…EPSS 1.1%9.8CVE-2021-21828Att xmill classic buffer overflow vulnerabilityA heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. In the default case …EPSS 1.1%9.8CVE-2021-21825Att xmill heap-based buffer overflow vulnerabilityA heap-based buffer overflow vulnerability exists in the XML Decompression PlainTextUncompressor::UncompressItem functionality of AT&T Labs’ Xmill 0.…EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2022-26507), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.