CVE-2017-2791 Information
Feb 14, 2021
cve
Description
JustSystems Ichitaro 2016 Trial contains a vulnerability that exists when trying to open a specially crafted PowerPoint file. Due to the application incorrectly handling the error case for a function’s result the application will use this result in a pointer calculation for reading file data into. Due to this the application will read data from the file into an invalid address thus corrupting memory. Under the right conditions this can lead to code execution under the context of the application.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/96440 http://www.talosintelligence.com/reports/TALOS-2016-0199/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: