Denial of Service Vulnerability in XnView MP on Windows
CVE-2019-9964

7.8HIGH

Key Information:

Vendor

Xnview

Status
Vendor
CVE Published:
24 March 2019

What is CVE-2019-9964?

A vulnerability exists in XnView MP 0.93.1 on Windows that allows remote attackers to initiate a denial of service, potentially leading to application crashes or other unspecified impacts. This issue is linked to the handling of crafted files, specifically in the function ntdll!RtlpNtMakeTemporaryKey, which can be exploited by unauthorized individuals to disrupt the normal functioning of the application.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.