CVE-2019-9865: Windriver Vxworks

High severity, CVSS 8.1. EPSS: 2% chance of exploitation in the next 30 days.

When RPC is enabled in Wind River VxWorks 6.9 prior to 6.9.1, a specially crafted RPC request can trigger an integer overflow leading to an out-of-bounds memory copy. It may allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code.

Affected products

  • Windriver Vxworks: from 6.9, before 6.9.1 (fixed in 6.9.1); version 6.6 only; version 6.7 only; version 6.8 only

Published 2019-05-29. Last modified 2026-06-17.