Vulnerabilities > CVE-2018-4040 - Access of Uninitialized Pointer vulnerability in Atlantiswordprocessor Atlantis Word Processor 3.2.7.2

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
atlantiswordprocessor
CWE-824

Summary

An exploitable uninitialized pointer vulnerability exists in the rich text format parser of Atlantis Word Processor, version 3.2.7.2. A specially crafted document can cause certain RTF tokens to dereference a pointer that has been uninitialized and then write to it. An attacker must convince a victim to open a specially crafted document in order to trigger this vulnerability.

Vulnerable Configurations

Part Description Count
Application
Atlantiswordprocessor
1

Common Weakness Enumeration (CWE)

Talos

idTALOS-2018-0713
last seen2019-05-29
published2018-11-20
reporterTalos Intelligence
sourcehttp://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0713
titleAtlantis Word Processor rich text format uninitialized TAutoList remote code execution vulnerability

The Hacker News

idTHN:256E89A426EB6F7EB8009CE059DA58AD
last seen2018-11-20
modified2018-11-20
published2018-11-20
reporterThe Hacker News
sourcehttps://thehackernews.com/2018/11/word-processor-vulnerability.html
title3 New Code Execution Flaws Discovered in Atlantis Word Processor