vendor:
FreeVimager
by:
Jean Pascal Pereira
7.5
CVSS
HIGH
Arbitrary Code Execution
CWE
Product Name: FreeVimager
Affected Version From: 4.1.2000
Affected Version To: 4.1.2000
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
FreeVimager 4.1.0 <= WriteAV Arbitrary Code Execution
This exploit allows an attacker to execute arbitrary code in FreeVimager version 4.1.0 or earlier. By crafting a specially designed GIF file and opening it with FreeVimager, the attacker can trigger the vulnerability and execute malicious code on the target system.
Mitigation:
Upgrade to a patched version of FreeVimager.