CVE-2017-7908: Ge Communicator

High severity, CVSS 7.6. EPSS: 1% chance of exploitation in the next 30 days.

A heap-based buffer overflow exists in the third-party product Gigasoft, v5 and prior, included in GE Communicator 3.15 and prior. A malicious HTML file that loads the ActiveX controls can trigger the vulnerability via unchecked function calls.

Affected products

  • Ge Ge Communicator: up to and including 3.15
  • Gigasoft Proessentials: up to and including 5

Published 2018-10-02. Last modified 2026-06-17.