Arbitrary Code Execution Vulnerability in IrfanView with BabaCAD4Image Plugin
CVE-2017-15760

7.8HIGH

Key Information:

Vendor

Irfanview

Vendor
CVE Published:
22 October 2017

What is CVE-2017-15760?

The vulnerability present in IrfanView 4.50 (64-bit) with the BabaCAD4Image plugin (version 1.3) allows attackers to execute arbitrary code or trigger a Denial of Service. This is accomplished through a specially crafted .dwg file that exploits a flaw in the handling of image data. Specifically, the flaw is associated with a User Mode Write AV near NULL, leading to severe security implications for users who interact with such files. It is essential for users to ensure they are using updated versions of this software to mitigate potential risks.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.