CVE-2021-27224: High severity irfanview vulnerability
Published Feb 17, 2021
·Updated
The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012ec6, which might allow remote attackers to execute arbitrary code.
Affected Software
2 affected components
IrfanView WPG<3.1.0.0
IrfanView IrfanView=4.57
Event History
Feb 17, 2021
CVE Published
via MITRE·03:44 PM
Data Sourced
via MITRE·03:44 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-27224?
CVE-2021-27224 has a high severity rating due to its ability to allow remote code execution.
2
How do I fix CVE-2021-27224?
To fix CVE-2021-27224, update the WPG plugin to version 3.1.0.0 or later.
3
What software is affected by CVE-2021-27224?
CVE-2021-27224 affects versions of the WPG plugin prior to 3.1.0.0 and IrfanView 4.57.
4
Can CVE-2021-27224 be exploited remotely?
Yes, CVE-2021-27224 can be exploited remotely by attackers to execute arbitrary code.
5
What kind of vulnerability is CVE-2021-27224?
CVE-2021-27224 is a user-mode write access violation vulnerability.