An exploitable out-of-bounds write vulnerability exists in the ico_read function of the igcore19d.dll library of Accusoft ImageGear 19.6.0. A specially crafted ICO file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.
2020-05-06T13:15:14.867
2024-11-21T05:35:03.637
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | accusoft | imagegear | 19.4.0 | Yes |
Application | accusoft | imagegear | 19.5.0 | Yes |
Application | accusoft | imagegear | 19.6.0 | Yes |