First published: Thu Jul 30 2020(Updated: )
DaviewIndy 8.98.7 and earlier version contain Use-After-Free vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.
Credit: vuln@krcert.or.kr
Affected Software | Affected Version | How to fix |
---|---|---|
Hmtalk Daviewindy | <=8.98.7 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7827 is a vulnerability in DaviewIndy 8.98.7 and earlier versions that allows for arbitrary code execution.
The Use-After-Free vulnerability in DaviewIndy is triggered when the user opens a malformed specific file that is mishandled by Daview.exe.
CVE-2020-7827 allows attackers to exploit the vulnerability and execute arbitrary code.
CVE-2020-7827 has a severity rating of 7.8 (high).
No, Microsoft Windows is not affected by CVE-2020-7827.
To fix CVE-2020-7827, it is recommended to update DaviewIndy to a version later than 8.98.7.