ZDI-26-552: OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18293.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-552?
ZDI-26-552 has a CVSS rating of 7.8, indicating a high severity risk.
How do I fix ZDI-26-552?
To mitigate ZDI-26-552, users should update to the latest version of OriginLab Origin Viewer that addresses this vulnerability.
What type of exploit is associated with ZDI-26-552?
ZDI-26-552 is associated with a remote code execution exploit that requires user interaction to be executed.
Who is affected by ZDI-26-552?
Users of affected installations of OriginLab Origin Viewer are vulnerable to ZDI-26-552.
What are the conditions for the exploitation of ZDI-26-552?
The exploitation of ZDI-26-552 requires the user to either visit a malicious website or open a compromised OPJ file.