PT-2019-10739 · Atlantis · Atlantis Word Processor
Published
2019-10-31
·
Updated
2023-02-04
·
CVE-2018-3983
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Atlantis Word Processor (affected versions not specified)
Description
The issue concerns an uninitialized pointer vulnerability in the Word document parser. It can be triggered by a specially crafted document, causing an array fetch to return an uninitialized pointer. This pointer is then used in arithmetic operations before writing a value to the result, potentially allowing an attacker to corrupt heap memory and execute code under the context of the application. The attacker must convince the victim to open the malicious document to exploit this issue.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Access of Uninitialized Pointer
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Atlantis Word Processor