Code Execution Vulnerability in IrfanView PDF Plugin by Irfan Skiljan
CVE-2017-15251

7.8HIGH

Key Information:

Vendor

Irfanview

Vendor
CVE Published:
11 October 2017

What is CVE-2017-15251?

The vulnerability in IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to potentially execute arbitrary code or disrupt service through the exploitation of a specially crafted PDF file. This occurs due to improper handling of data related to 'Faulting Address controls Code Flow', which can lead to significant security risks for users interacting with malicious PDF documents.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.