CVE-2022-40660

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Sep 15, 2022
Updated: Jan 7, 2025
CWE ID 122

Summary

CVE-2022-40660 is a remote code execution vulnerability affecting NIKON NIS-Elements Viewer version 1.2100.1483.0. This issue allows attackers to execute arbitrary code by exploiting a flaw in the parsing of PSD images. The vulnerability stems from insufficient validation of user-supplied data, leading to a heap-based buffer overflow. Exploitation requires user interaction, such as visiting a malicious webpage or opening a malicious file. Successful exploitation grants the attacker the ability to execute code in the context of the affected process. (ZDI-CAN-15135)

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share