PT-2021-17333 · Irfanview · Wpg Plugin
Samandeep Singh
·
Published
2021-02-17
·
Updated
2021-02-22
·
CVE-2021-27224
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
WPG plugin versions prior to 3.1.0.0 for IrfanView 4.57
Description:
The issue is related to a user-mode write access violation, which could potentially allow remote attackers to execute arbitrary code. This violation occurs starting at a specific memory address.
Recommendations:
For WPG plugin versions prior to 3.1.0.0, update to version 3.1.0.0 or later to resolve the issue.
Exploit
Fix
RCE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpg Plugin