Remote Code Execution in OpenText Brava! Desktop by OpenText
CVE-2021-31491
7.8HIGH
Summary
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. Exploitation requires user interaction, as the target must either visit a malicious webpage or open a corrupt file. The flaw lies in the improper validation of user-supplied DWF files, which can lead to a buffer overflow. An attacker can exploit this oversight to execute code within the context of the application, potentially compromising system integrity and confidentiality.
Affected Version(s)
Brava! Desktop 16.6.3.84
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
rgod