PT-2018-1607 · Atlantis · Atlantis Word Processor

Published

2018-09-10

·

Updated

2023-02-04

·

CVE-2018-4001

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Atlantis Word Processor version 3.2.5.0
Description The issue is related to an uninitialized pointer vulnerability in the Office Open XML parser. It can be triggered by a specially crafted document, causing an uninitialized pointer to be assigned to a variable, which is later dereferenced and written to, allowing for controlled heap corruption and potentially leading to code execution under the context of the application. An attacker must convince a victim to open a malicious document to exploit this issue.
Recommendations For Atlantis Word Processor version 3.2.5.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Access of Uninitialized Pointer

Weakness Enumeration

Related Identifiers

BDU:2018-01166
CVE-2018-4001

Affected Products

Atlantis Word Processor