Image Viewer CP Pro Gold ActiveX Buffer Overflow

Strike ID:
E13-8nd01
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
t
Variants:
1
Year:
2013

Description

This strike exploits a vulnerability inside an ActiveX control within Image Viewer. If an overly long string is passed to the TIFMergeMultiFiles method, a buffer can overflow allowing for remote code execution.

CVE