Arbitrary Code Execution and Denial of Service Vulnerability in XnView Classic for Windows Version 2.43 via Crafted .dwg File

Arbitrary Code Execution and Denial of Service Vulnerability in XnView Classic for Windows Version 2.43 via Crafted .dwg File

CVE-2017-15785 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "Data Execution Prevention Violation near NULL starting at Unknown Symbol @ 0x0000000000000000 called from CADImage+0x0000000000286a79."

Learn more about our Web Application Penetration Testing UK.