Vulnerability Description
The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012ec6, which might allow remote attackers to execute arbitrary code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Irfanview | Wpg | < 3.1.0.0 |
| Irfanview | Irfanview | 4.57 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/161449/IrfanView-4.57-Denial-Of-Service-CodExploitThird Party AdvisoryVDB Entry
- https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-irfaExploitThird Party Advisory
- https://www.irfanview.com/plugins.htmVendor Advisory
- http://packetstormsecurity.com/files/161449/IrfanView-4.57-Denial-Of-Service-CodExploitThird Party AdvisoryVDB Entry
- https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-irfaExploitThird Party Advisory
- https://www.irfanview.com/plugins.htmVendor Advisory
FAQ
What is CVE-2021-27224?
CVE-2021-27224 is a vulnerability with a CVSS score of 7.5 (HIGH). The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012ec6, which might allow remote attackers to execute arbitrary code.
How severe is CVE-2021-27224?
CVE-2021-27224 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27224?
Check the references section above for vendor advisories and patch information. Affected products include: Irfanview Wpg, Irfanview Irfanview.