First published: Wed Jul 05 2017(Updated: )
IrfanView version 4.44 (32bit) with TOOLS plugin 4.50 allows attackers to execute arbitrary code or cause a denial of service via a crafted file, related to a "Read Access Violation on Block Data Move starting at ntdll_77df0000!memcpy+0x0000000000000033."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IrfanView IrfanView | =4.44 | |
Irfanview Tools | =4.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9915 is classified as a critical vulnerability due to the potential for arbitrary code execution.
To mitigate CVE-2017-9915, users should update to IrfanView version 4.45 or higher and ensure the TOOLS plugin is updated to a safe version.
CVE-2017-9915 can result in arbitrary code execution or a denial of service, compromising the affected system.
IrfanView version 4.44 and TOOLS plugin version 4.50 are specifically affected by CVE-2017-9915.
Attackers can exploit CVE-2017-9915 by sending crafted files that trigger a read access violation during data processing.