User Mode Write Vulnerability in IrfanView PDF Plugin by Irfan Skiljan
CVE-2017-15253
7.8HIGH
What is CVE-2017-15253?
IrfanView version 4.44 (32bit), when used with PDF plugin version 4.43, is susceptible to a user mode write vulnerability. An attacker can exploit this flaw by crafting a malicious PDF file, which may lead to arbitrary code execution on the affected system or cause a denial of service. This issue stems from improper handling of global state in the PDF processing component, specifically at the function PDF!xmlGetGlobalState.
