Stack Buffer Overflow Vulnerability in MuseScore by MuseScore
CVE-2023-26923

7HIGH

Key Information:

Vendor

Musescore

Status
Vendor
CVE Published:
28 March 2023

What is CVE-2023-26923?

A stack buffer overflow vulnerability exists in MuseScore versions 3.0 to 4.0.1. This flaw occurs when the application processes improperly configured MIDI files. An attacker can exploit this vulnerability by supplying malicious MIDI data, potentially leading to the execution of arbitrary code on the affected system. It is crucial for users to update to the latest version to mitigate this risk and enhance overall security.

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.