Vulnerabilities > CVE-2018-4000 - Double Free vulnerability in Atlantiswordprocessor Atlantis Word Processor 3.2.5.0

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
atlantiswordprocessor
CWE-415

Summary

An exploitable double-free vulnerability exists in the Office Open XML parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted document can cause a TTableRow instance to be referenced twice, resulting in a double-free vulnerability when both the references go out of scope. An attacker must convince a victim to open a document in order to trigger this vulnerability.

Vulnerable Configurations

Part Description Count
Application
Atlantiswordprocessor
1

Common Weakness Enumeration (CWE)

Talos

idTALOS-2018-0668
last seen2019-05-29
published2018-10-01
reporterTalos Intelligence
sourcehttp://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0668
titleAtlantis Word Processor Office Open XML TTableRow double free code execution vulnerability