First published: Fri Oct 01 2021(Updated: )
Word97Import200.dll in Corel WordPerfect 2020 20.0.0.200 is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious DOC file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Corel WordPerfect 2020 | =20.0.0.200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38110 is an Out-of-bounds Write vulnerability affecting Corel WordPerfect 2020 version 20.0.0.200.
CVE-2021-38110 has a severity score of 7.8, which is considered high.
CVE-2021-38110 allows an unauthenticated attacker to achieve arbitrary code execution in the context of the current user by exploiting an Out-of-bounds Write vulnerability in Word97Import200.dll when parsing a crafted file.
The CVE-2021-38110 vulnerability can be exploited by an attacker who sends a specially crafted file to a user of Corel WordPerfect 2020, allowing the attacker to execute arbitrary code on the target system.
At the time of this writing, there is no information available about a fix or patch for CVE-2021-38110 in Corel WordPerfect 2020. It is recommended to follow the vendor's security advisories for updates.