User Mode Write Vulnerability in XnView Classic by XnView
CVE-2019-17262

7.8HIGH

Key Information:

Vendor

Xnview

Status
Vendor
CVE Published:
8 October 2019

What is CVE-2019-17262?

XnView Classic version 2.49.1 is affected by a user mode write vulnerability that can be exploited during specific operations, starting at a defined point in memory (Xwsq+0x0000000000001fc0). This flaw could potentially allow attackers to manipulate the application’s memory, leading to unexpected behaviors or crashes. Users of this software should consider applying the appropriate updates available in the official changelog to mitigate any risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.