Stack-based Buffer Overflow in FastStone Image Viewer Allows Code Execution
CVE-2021-26236

7.8HIGH

Key Information:

Vendor

Faststone

Vendor
CVE Published:
18 March 2021

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2021-26236?

FastStone Image Viewer versions up to and including 7.5 have a vulnerability due to a stack-based buffer overflow, particularly in the handling of CUR file parsing. This weakness lies in the manipulation of the BITMAPINFOHEADER structure, specifically affecting the 'BitCount' field. If an attacker manages to entice a user into opening or previewing a specially crafted CUR file, they can exploit this flaw, potentially leading to arbitrary code execution by corrupting the Structure Exception Handler (SEH). This poses significant risks to users who may inadvertently execute malicious code through seemingly benign CUR files.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.