Denial of Service Vulnerability in XnView MP on Windows
CVE-2019-9963

7.8HIGH

Key Information:

Vendor

Xnview

Status
Vendor
CVE Published:
24 March 2019

What is CVE-2019-9963?

A vulnerability in XnView MP 0.93.1 for Windows allows remote attackers to exploit application crashes or potentially cause unspecified impacts by delivering crafted files. This vulnerability is associated with memory handling within the ntdll!RtlFreeHeap function, highlighting a critical security risk for users of the application. Prompt updates and cautious handling of untrusted files are advised to mitigate potential threats.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.