Vulnerability Description
An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 14.0.7 x64. A specially crafted BMP file can cause an out-of-bounds memory write, allowing a potential attacker to execute arbitrary code on the victim machine. Can trigger this vulnerability by sending the user a specially crafted BMP file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Investintech | Able2Extract | 14.0.7 |
Related Weaknesses (CWE)
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0880ExploitThird Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0880ExploitThird Party Advisory
FAQ
What is CVE-2019-5088?
CVE-2019-5088 is a vulnerability with a CVSS score of 7.8 (HIGH). An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 14.0.7 x64. A specially crafted BMP file can cause an out-of-bounds memory write, allowing a potential a...
How severe is CVE-2019-5088?
CVE-2019-5088 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-5088?
Check the references section above for vendor advisories and patch information. Affected products include: Investintech Able2Extract.