CVE-2021-26233: High severity faststone image viewer vulnerability
FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfcb, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26233?
CVE-2021-26233 is rated as a medium severity vulnerability due to its potential for Denial of Service and possible code execution.
How do I fix CVE-2021-26233?
To fix CVE-2021-26233, update FastStone Image Viewer to version 7.6 or later.
What types of attacks can exploit CVE-2021-26233?
CVE-2021-26233 can be exploited for Denial of Service attacks and potentially code execution through specially crafted CUR files.
Which versions of FastStone Image Viewer are affected by CVE-2021-26233?
FastStone Image Viewer versions up to and including 7.5 are affected by CVE-2021-26233.
What could happen if I am still using FastStone Image Viewer version 7.5 or earlier with CVE-2021-26233?
Using FastStone Image Viewer version 7.5 or earlier may expose your system to crashes or unauthorized code execution when opening malicious CUR files.