Remote Code Execution in OpenText Brava! Desktop by OpenText
CVE-2021-31491

7.8HIGH

Key Information:

Vendor
Opentext
Vendor
CVE Published:
15 June 2021

Summary

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. Exploitation requires user interaction, as the target must either visit a malicious webpage or open a corrupt file. The flaw lies in the improper validation of user-supplied DWF files, which can lead to a buffer overflow. An attacker can exploit this oversight to execute code within the context of the application, potentially compromising system integrity and confidentiality.

Affected Version(s)

Brava! Desktop 16.6.3.84

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rgod
.