CVE-2024-11533
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Nov 22, 2024
Updated: Nov 25, 2024
CWE ID 787
Summary
CVE-2024-11533 is a remote code execution vulnerability affecting IrfanView. This issue arises from an out-of-bounds write flaw in the software's DXF file parsing functionality. The lack of proper data validation allows an attacker to write data beyond the allocated buffer, enabling the execution of arbitrary code. User interaction is necessary for exploitation, either through visiting a malicious webpage or opening a tainted file. The ZDI-CAN-24616 disclosure preceded this CVE.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.