Out-Of-Bounds Write Vulnerability in IrfanView Product by Irfan Skiljan
CVE-2024-6821

7.8HIGH

Key Information:

Vendor

Irfanview

Status
Vendor
CVE Published:
22 November 2024

What is CVE-2024-6821?

A vulnerability exists in IrfanView related to the parsing of CIN files, which allows remote attackers to exploit this flaw by enticing users to visit a malicious page or open a specially crafted file. The issue stems from inadequate validation of user-supplied data, enabling an out-of-bounds write that can result in arbitrary code execution within the context of the current process. Protective measures are necessary to mitigate this risk and ensure safe usage of the affected product.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.