Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40696
HistoryMay 26, 2023 - 5:48 a.m.

Remote Code Execution (RCE)

2023-05-2605:48:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
22
remote code execution
system.drawing.common
vulnerability
macos
linux
graphic files

EPSS

0.017

Percentile

88.0%

System.Drawing.Common is vulnerable to Remote Code Execution (RCE). The vulnerability exists because the library does not add the reference count to the graphics metafiles, which allows an attacker to inject and execute malicious code by providing maliciously crafted graphic files. This vulnerability only exists on systems running on MacOS or Linux.