First published: Tue Nov 05 2019(Updated: )
An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 4.0.7 x64. A specially crafted JPEG file can cause an out-of-bounds memory write, allowing an attacker to execute arbitrary code on the victim machine. An attacker could exploit a vulnerability by providing the user with a specially crafted JPEG file.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Investintech Able2Extract | =14.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5089 is a memory corruption vulnerability in Investintech Able2Extract Professional 4.0.7 x64.
CVE-2019-5089 has a severity rating of 7.8 (high).
CVE-2019-5089 can be exploited by providing a specially crafted JPEG file that triggers an out-of-bounds memory write, potentially allowing the execution of arbitrary code on the victim machine.
Investintech Able2Extract Professional 14.0.7 x64 is affected by CVE-2019-5089.
It is recommended to update to the latest version of Investintech Able2Extract Professional to mitigate the vulnerability.