First published: Sat Sep 30 2017(Updated: )
Artifex GSView 6.0 Beta on Windows allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Block Data Move starting at mupdfnet64!mIncrementalSaveFile+0x0000000000193359."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex GSView | =6.0-beta | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14947 has a high severity level due to its potential to allow arbitrary code execution.
To fix CVE-2017-14947, update to the latest stable version of Artifex GSView or ensure you are not using the vulnerable 6.0 Beta version.
CVE-2017-14947 can lead to arbitrary code execution or a denial of service through specially crafted .xps files.
CVE-2017-14947 specifically affects Artifex GSView version 6.0 Beta on Windows.
To mitigate risks from CVE-2017-14947, avoid opening untrusted .xps files with the affected application version.