Vulnerabilities > CVE-2017-7894 - Unspecified vulnerability in Windjview Project Windjview 2.1
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
WinDjView 2.1 might allow user-assisted attackers to execute code via a crafted .djvu file, because of a "User Mode Write AV near NULL" in WinDjView.exe. One threat model is a victim who obtains an untrusted .djvu file from a remote location and issues several user-defined commands.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |