PT-2019-10739 · Atlantis · Atlantis Word Processor

Published

2019-10-31

·

Updated

2023-02-04

·

CVE-2018-3983

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Atlantis Word Processor (affected versions not specified)
Description The issue concerns an uninitialized pointer vulnerability in the Word document parser. It can be triggered by a specially crafted document, causing an array fetch to return an uninitialized pointer. This pointer is then used in arithmetic operations before writing a value to the result, potentially allowing an attacker to corrupt heap memory and execute code under the context of the application. The attacker must convince the victim to open the malicious document to exploit this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Access of Uninitialized Pointer

Weakness Enumeration

Related Identifiers

CVE-2018-3983

Affected Products

Atlantis Word Processor