First published: Mon Sep 18 2017(Updated: )
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, related to a "User Mode Write AV starting at STDUDjVuFile!DllUnregisterServer+0x000000000000d9a9."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Stdutility Stdu Viewer | =1.6.375 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14552 has been classified with a high severity due to its potential to allow arbitrary code execution.
To remediate CVE-2017-14552, it is recommended to update to the latest version of STDU Viewer that addresses this vulnerability.
CVE-2017-14552 allows for remote code execution or denial of service attacks through specially crafted .djvu files.
STDU Viewer version 1.6.375 is confirmed to be affected by CVE-2017-14552.
Yes, CVE-2017-14552 can be easily exploited by attackers who can deliver a malicious .djvu file to the user.