An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially crafted message to 127.0.0.1:7153. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.
https://www.tenable.com/security/research/tra-2020-71
https://www.tenable.com/security/research/tra-2020-71
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-5806