CVE-2021-26236
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
FastStone Image Viewer v.<= 7.5 is affected by a Stack-based Buffer Overflow at 0x005BDF49, affecting the CUR file parsing functionality (BITMAPINFOHEADER Structure, 'BitCount' file format field), that will end up corrupting the Structure Exception Handler (SEH). Attackers could exploit this issue to achieve code execution when a user opens or views a malformed/specially crafted CUR file.
FastStone Image Viewer versiones anteriores incluyendo a 7.5, está afectado por un desbordamiento del búfer en la región stack de la memoria en 0x005BDF49, que afecta la funcionalidad de análisis de archivos CUR (estructura BITMAPINFOHEADER, campo de formato de archivo "BitCoun"), que terminará corrompiendo el Structure Exception Handler (SEH) . Unos atacantes podrían explotar este problema para lograr una ejecución de código cuando un usuario abre o visualiza un archivo CUR malformado o especialmente diseñado
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-25 CVE Reserved
- 2021-03-18 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Faststone Search vendor "Faststone" | Image Viewer Search vendor "Faststone" for product "Image Viewer" | <= 7.5 Search vendor "Faststone" for product "Image Viewer" and version " <= 7.5" | - |
Affected
|