Bandisoft ARK Library Out-of-bound Vulnerability
CVE-2021-26623

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
1 April 2022

What is CVE-2021-26623?

A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter length value in the ark library. Remote attackers can induce exploit malicious code using this function.

Affected Version(s)

Bandizip Windows <= 7.19

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-26623 : Bandisoft ARK Library Out-of-bound Vulnerability