CVE-2021-38107: Medium severity Corel Coreldraw 2020 vulnerability
CdrCore.dll in Corel DrawStandard 2020 22.0.0.474 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to access unauthorized system memory in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious CDR file.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-38107.
What is the affected software version?
The affected software version is Corel DrawStandard 2020 22.0.0.474.
What is the severity rating of CVE-2021-38107?
The severity rating of CVE-2021-38107 is 5.5 (medium).
How does this vulnerability occur?
This vulnerability occurs when a crafted file is parsed by CdrCore.dll in Corel DrawStandard 2020 22.0.0.474.
How can an attacker exploit this vulnerability?
An unauthenticated attacker can exploit this vulnerability to access unauthorized system memory in the context of the current user.