First published: Thu Mar 18 2021(Updated: )
FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfc9, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FastStone Image Viewer | <=7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for FastStone Image Viewer is CVE-2021-26235.
The severity of CVE-2021-26235 is high with a CVSS score of 7.8.
CVE-2021-26235 affects FastStone Image Viewer by causing a user mode write access violation near NULL, which can lead to a Denial of Service (DoS) or possibly code execution.
An attacker can exploit CVE-2021-26235 by providing a malformed CUR file that is mishandled by FSViewer.exe, resulting in a user mode write access violation.
At the time of writing, there may not be a fix available for CVE-2021-26235. It is recommended to update to the latest version of FastStone Image Viewer or apply any patches or mitigations provided by the vendor.