First published: Fri Oct 01 2021(Updated: )
Word97Import200.dll in Corel WordPerfect 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to access unauthorized system memory in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious DOC file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Corel WordPerfect 2020 | =20.0.0.200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38108 is a vulnerability in Corel WordPerfect 2020 version 20.0.0.200 that allows an unauthenticated attacker to access unauthorized system memory.
CVE-2021-38108 affects Corel WordPerfect 2020 by allowing an attacker to exploit an out-of-bounds read vulnerability when parsing a crafted file.
CVE-2021-38108 has a severity keyword of 'medium' and a severity value of 5.5.
An attacker can exploit CVE-2021-38108 by leveraging the out-of-bounds read vulnerability in Word97Import200.dll when parsing a specially crafted file.
Corel WordPerfect 2020 version 20.0.0.200 is affected by CVE-2021-38108, but there is no information available regarding a fix or patch at the moment.