Vulnerabilities > CVE-2019-5088 - Out-of-bounds Write vulnerability in Investintech Able2Extract 14.0.7

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
investintech
CWE-787

Summary

An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 14.0.7 x64. A specially crafted BMP file can cause an out-of-bounds memory write, allowing a potential attacker to execute arbitrary code on the victim machine. Can trigger this vulnerability by sending the user a specially crafted BMP file.

Vulnerable Configurations

Part Description Count
Application
Investintech
1

Common Weakness Enumeration (CWE)

Talos

idTALOS-2019-0880
last seen2019-11-09
published2019-11-04
reporterTalos Intelligence
sourcehttp://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0880
titleInvestintech Able2Extract Professional BMP decoding biClrUsed code execution vulnerability