ID

VAR-202203-2044


TITLE

(0Day) Ecava IntegraXor Inkscape WMF File Parsing Memory Corruption Remote Code Execution Vulnerability

Trust: 0.7

sources: ZDI: ZDI-22-490

DESCRIPTION

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ecava IntegraXor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the parsing of WMF files within the Inkscape component. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current process.

Trust: 0.7

sources: ZDI: ZDI-22-490

AFFECTED PRODUCTS

vendor:ecavamodel:integraxorscope: - version: -

Trust: 0.7

sources: ZDI: ZDI-22-490

CVSS

SEVERITY

CVSSV2

CVSSV3

ZDI: ZDI-22-490
value: HIGH

Trust: 0.7

ZDI: ZDI-22-490
baseSeverity: HIGH
baseScore: 7.8
vectorString: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 0.7

sources: ZDI: ZDI-22-490

EXTERNAL IDS

db:ZDI_CANid:ZDI-CAN-14444

Trust: 0.7

db:ZDIid:ZDI-22-490

Trust: 0.7

sources: ZDI: ZDI-22-490

CREDITS

Tran Van Khang - khangkito (VinCSS)

Trust: 0.7

sources: ZDI: ZDI-22-490

SOURCES

db:ZDIid:ZDI-22-490

LAST UPDATE DATE

2022-05-17T02:00:58.949000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-22-490date:2022-03-29T00:00:00

SOURCES RELEASE DATE

db:ZDIid:ZDI-22-490date:2022-03-09T00:00:00