CVE-2023-39453
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2023-39453 is a use-after-free vulnerability identified in the tif_parse_sub_IFD functionality of Accusoft ImageGear 20.1. This issue arises when the software fails to properly manage memory, allowing a maliciously crafted TIFF file to cause arbitrary code execution. An attacker can exploit this vulnerability by delivering a specially crafted TIFF file to an unsuspecting user or system. Successful exploitation could result in significant security risks, including unauthorized system access or data theft. Users of Accusoft ImageGear 20.1 are urged to update to a patched version as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Accusoft Corp