ZDI-26-553: OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18294.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-553?
The severity of ZDI-26-553 is categorized with a CVSS rating of 7.8, indicating a high risk.
How can I fix ZDI-26-553?
To fix ZDI-26-553, ensure you are using the latest version of OriginLab Origin Viewer that addresses this vulnerability.
What is the exploit mechanism for ZDI-26-553?
ZDI-26-553 can be exploited by convincing the user to visit a malicious page or open a malicious OGW file.
What types of attacks are possible with ZDI-26-553?
ZDI-26-553 allows remote code execution, enabling attackers to execute arbitrary code on vulnerable systems.
Who is affected by ZDI-26-553?
Users of OriginLab Origin Viewer are affected by ZDI-26-553 if they do not apply the necessary security updates.