Arbitrary Code Execution and Denial of Service Vulnerability in XnView Classic 2.41 via Crafted .jb2 File

Arbitrary Code Execution and Denial of Service Vulnerability in XnView Classic 2.41 via Crafted .jb2 File

CVE-2017-14580 · MEDIUM Severity

AV:L/AC:L/AU:N/C:P/I:P/A:P

XnView Classic for Windows Version 2.41 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at jbig2dec+0x000000000000870f."

Learn more about our User Device Pen Test.