PT-2017-17978 · Windjview · Windjview
Published
2017-07-05
·
Updated
2019-10-03
·
CVE-2017-7894
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WinDjView version 2.1
Description
The issue allows user-assisted attackers to execute code via a crafted .djvu file, because of a "User Mode Write AV near NULL" in WinDjView.exe. A possible threat model involves a victim obtaining an untrusted .djvu file from a remote location and issuing several user-defined commands.
Recommendations
For WinDjView version 2.1, consider avoiding the use of untrusted .djvu files and refrain from issuing user-defined commands on potentially malicious files until a fix is available. As a temporary workaround, restrict the execution of commands related to .djvu files to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windjview