PT-2020-2720 · Accusoft · Imagegear

Published

2020-01-30

·

Updated

2022-07-28

·

CVE-2020-6076

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Accusoft ImageGear version 19.5.0
Description The issue is related to an out-of-bounds write vulnerability in the igcore19d.dll ICO icoread parser of the ImageGear library. This vulnerability can be exploited by a remote attacker using a specially crafted ICO file, potentially leading to remote code execution. The attacker needs to provide a malformed file to the victim to trigger the issue.
Recommendations For Accusoft ImageGear version 19.5.0, consider avoiding the use of the IG load file function or restricting access to the ICO file parsing functionality until a patch is available. As a temporary workaround, refrain from processing untrusted or specially crafted ICO files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02796
CVE-2020-6076

Affected Products

Imagegear