Arbitrary Code Execution Vulnerability in IrfanView with PDF Plugin
CVE-2017-15248

7.8HIGH

Key Information:

Vendor

Irfanview

Vendor
CVE Published:
11 October 2017

What is CVE-2017-15248?

A vulnerability in IrfanView version 4.44 (32bit) with the PDF plugin version 4.43 allows attackers to manipulate a specially crafted PDF file. When such a file is opened, it can exploit improper handling of data from faulting addresses, leading to arbitrary code execution or potentially a denial of service. This poses significant risks as attackers can execute unwanted commands on the system or crash the application, highlighting the need for immediate attention to ensure software security.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.