ZDI-23-866: (0Day) Ashlar-Vellum Graphite VC6 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-866?
The severity of ZDI-23-866 is considered high due to the potential for remote code execution.
How do I fix ZDI-23-866?
To fix ZDI-23-866, ensure that you update to the latest version of Ashlar-Vellum Graphite as provided by the vendor.
What types of attacks can be executed via ZDI-23-866?
ZDI-23-866 enables attackers to execute arbitrary code by convincing users to visit malicious pages or open harmful files.
Is user interaction required for ZDI-23-866 exploitation?
Yes, user interaction is required for exploiting ZDI-23-866 as the target must engage with malicious content.
Which product is affected by ZDI-23-866?
The affected product by ZDI-23-866 is Ashlar-Vellum Graphite.