Lucene search

K
zdiMichael DePlante (@izobashi) of Trend Micro's Zero Day InitiativeZDI-22-1471
HistoryOct 25, 2022 - 12:00 a.m.

(0Day) Corel CorelDRAW Graphics Suite CGM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability

2022-10-2500:00:00
Michael DePlante (@izobashi) of Trend Micro's Zero Day Initiative
www.zerodayinitiative.com
12
remote code execution
corel
coreldraw graphics suite
cgm file
stack-based buffer overflow
user interaction
malicious file
arbitrary code
validation
data length
current process

0.001 Low

EPSS

Percentile

49.6%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CGM files. When parsing CGM files, the process does not properly validate the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

0.001 Low

EPSS

Percentile

49.6%

Related for ZDI-22-1471