{"api_version":"1","generated_at":"2026-07-23T13:44:15+00:00","cve":"CVE-2023-42138","urls":{"html":"https://cve.report/CVE-2023-42138","api":"https://cve.report/api/cve/CVE-2023-42138.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-42138","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-42138"},"summary":{"title":"CVE-2023-42138","description":"Out-of-bounds read vulnerability exists in KV STUDIO Ver. 11.62 and earlier and KV REPLAY VIEWER Ver. 2.62 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user of KV STUDIO PLAYER open a specially crafted file.","state":"PUBLIC","assigner":"vultures@jpcert.or.jp","published_at":"2023-10-11 09:15:00","updated_at":"2023-10-18 19:57:00"},"problem_types":["CWE-125"],"metrics":[],"references":[{"url":"https://www.keyence.com/vulnerability231001","name":"https://www.keyence.com/vulnerability231001","refsource":"MISC","tags":[],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"404"},{"url":"https://jvn.jp/en/vu/JVNVU94752076/index.html","name":"https://jvn.jp/en/vu/JVNVU94752076/index.html","refsource":"MISC","tags":[],"title":"JVNVU#94752076: Out-of-bounds read vulnerability in Keyence KV STUDIO and KV REPLAY VIEWER","mime":"text/xml","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-42138","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-42138","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"42138","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"keyence","cpe5":"kv_replay_viewer","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"42138","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"keyence","cpe5":"kv_studio","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-42138","ASSIGNER":"vultures@jpcert.or.jp","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"Out-of-bounds read vulnerability exists in KV STUDIO Ver. 11.62 and earlier and KV REPLAY VIEWER Ver. 2.62 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user of KV STUDIO PLAYER open a specially crafted file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Out-of-bounds read"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"KEYENCE CORPORATION","product":{"product_data":[{"product_name":"KV STUDIO","version":{"version_data":[{"version_affected":"=","version_value":"Ver. 11.62 and earlier"}]}},{"product_name":"KV REPLAY VIEWER","version":{"version_data":[{"version_affected":"=","version_value":"Ver. 2.62 and earlier"}]}}]}}]}},"references":{"reference_data":[{"url":"https://www.keyence.com/vulnerability231001","refsource":"MISC","name":"https://www.keyence.com/vulnerability231001"},{"url":"https://jvn.jp/en/vu/JVNVU94752076/index.html","refsource":"MISC","name":"https://jvn.jp/en/vu/JVNVU94752076/index.html"}]}},"nvd":{"publishedDate":"2023-10-11 09:15:00","lastModifiedDate":"2023-10-18 19:57:00","problem_types":["CWE-125"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:keyence:kv_replay_viewer:*:*:*:*:*:*:*:*","versionEndExcluding":"2.63","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:keyence:kv_studio:*:*:*:*:*:*:*:*","versionEndExcluding":"11.63","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}