Arbitrary Code Execution Vulnerability in IrfanView with BabaCAD4Image Plugin
CVE-2017-15758

7.8HIGH

Key Information:

Vendor

Irfanview

Vendor
CVE Published:
22 October 2017

What is CVE-2017-15758?

The IrfanView image viewer, specifically version 4.50 for 64-bit systems with the BabaCAD4Image plugin (version 1.3), contains a vulnerability that can be exploited by attackers. This flaw allows for the execution of arbitrary code or the triggering of a denial of service condition when a specially crafted .dwg file is processed. The issue arises due to improper handling of data from a faulting address, which can lead to unintended execution paths. It is crucial for users to be aware of this vulnerability and implement necessary updates to mitigate potential risks.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.