CVE-2021-38108: Medium severity Corel WordPerfect 2020 vulnerability
Word97Import200.dll in Corel WordPerfect 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to access unauthorized system memory in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious DOC file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-38108?
CVE-2021-38108 is a vulnerability in Corel WordPerfect 2020 version 20.0.0.200 that allows an unauthenticated attacker to access unauthorized system memory.
How does CVE-2021-38108 impact Corel WordPerfect 2020?
CVE-2021-38108 affects Corel WordPerfect 2020 by allowing an attacker to exploit an out-of-bounds read vulnerability when parsing a crafted file.
What is the severity of CVE-2021-38108?
CVE-2021-38108 has a severity keyword of 'medium' and a severity value of 5.5.
How can an attacker exploit CVE-2021-38108?
An attacker can exploit CVE-2021-38108 by leveraging the out-of-bounds read vulnerability in Word97Import200.dll when parsing a specially crafted file.
Is there a fix for CVE-2021-38108 in Corel WordPerfect 2020?
Corel WordPerfect 2020 version 20.0.0.200 is affected by CVE-2021-38108, but there is no information available regarding a fix or patch at the moment.