PT-2020-5978 · Microsoft · Raw Image Extension

Wenguang Jiao

·

Published

2020-12-20

·

Updated

2023-12-29

·

CVE-2021-28468

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Raw Image Extension (affected versions not specified)
Description The issue is related to errors in data type conversion during the parsing of CR3 files by the Raw Image Extension plugin. This can be exploited by an attacker to execute arbitrary code using a specially crafted malicious web page or a specially crafted malicious file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Type Confusion

Weakness Enumeration

Related Identifiers

BDU:2021-02201
CVE-2021-28468
ZDI-21-421

Affected Products

Raw Image Extension