Arbitrary Code Execution Vulnerability in IrfanView with CADImage Plugin
CVE-2017-15739

7.8HIGH

Key Information:

Vendor

Irfanview

Vendor
CVE Published:
22 October 2017

What is CVE-2017-15739?

The reported vulnerability in IrfanView 4.50 with CADImage plugin allows an attacker to execute arbitrary code or trigger a denial of service condition by manipulating a specially crafted .dwg file. This exploit occurs due to improper handling of data from a faulting address, which impacts subsequent memory operations. The flaw presents significant risks for users as it can lead to unauthorized access and control of the affected system.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.