FastStone Image Viewer PSD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
CVE-2024-9112
7.8HIGH
What is CVE-2024-9112?
A vulnerability exists in FastStone Image Viewer related to PSD file parsing that allows remote attackers to execute arbitrary code. The flaw stems from inadequate validation of user-supplied data during the parsing process, which can lead to an out-of-bounds write. To successfully exploit this vulnerability, a user must visit a malicious web page or open a compromised PSD file. Once exploited, an attacker could execute code within the context of the current process, potentially leading to further unauthorized access and control over the system.
Affected Version(s)
Image Viewer 7.8
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
CVSS V3.0
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
