CVE-2020-6082
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An exploitable out-of-bounds write vulnerability exists in the ico_read function of the igcore19d.dll library of Accusoft ImageGear 19.6.0. A specially crafted ICO file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.
Se presenta una vulnerabilidad de escritura fuera de límites explotable en la función ico_read de la biblioteca igcore19d.dll de Accusoft ImageGear versión 19.6.0. Un archivo ICO especialmente diseñado puede causar una escritura fuera de límites, resultando en una ejecución de código remota. Un atacante necesita proporcionar un archivo con formato malformado a la víctima para desencadenar la vulnerabilidad.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-07 CVE Reserved
- 2020-05-06 CVE Published
- 2024-06-15 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1004 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Accusoft Search vendor "Accusoft" | Imagegear Search vendor "Accusoft" for product "Imagegear" | 19.4.0 Search vendor "Accusoft" for product "Imagegear" and version "19.4.0" | - |
Affected
| ||||||
Accusoft Search vendor "Accusoft" | Imagegear Search vendor "Accusoft" for product "Imagegear" | 19.5.0 Search vendor "Accusoft" for product "Imagegear" and version "19.5.0" | - |
Affected
| ||||||
Accusoft Search vendor "Accusoft" | Imagegear Search vendor "Accusoft" for product "Imagegear" | 19.6.0 Search vendor "Accusoft" for product "Imagegear" and version "19.6.0" | - |
Affected
|