Vulnerability Description
A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter length value in the ark library. Remote attackers can induce exploit malicious code using this function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bandisoft | Bandizip | < 7.19 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66595Third Party Advisory
- https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66595Third Party Advisory
FAQ
What is CVE-2021-26623?
CVE-2021-26623 is a vulnerability with a CVSS score of 7.8 (HIGH). A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter length value in the ark library. Remote attackers can induce exploit malicious code ...
How severe is CVE-2021-26623?
CVE-2021-26623 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26623?
Check the references section above for vendor advisories and patch information. Affected products include: Bandisoft Bandizip, Microsoft Windows.