Denial of Service Vulnerability in XnView Classic for Windows
CVE-2019-9968

7.8HIGH

Key Information:

Vendor

Xnview

Vendor
CVE Published:
24 March 2019

What is CVE-2019-9968?

XnView Classic 2.48 for Windows is vulnerable to a denial of service that can be triggered by remote attackers using a specially crafted file. This vulnerability can lead to an application crash, creating potential disruptions for users. It affects the way the application handles tasks in the ntdll library, specifically the RtlQueueWorkItem function, making it susceptible to exploitation through remote means.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.