Impact
OriginLab OriginPro has a flaw in its OPJU file parsing routine that allows an out-of-bounds write, classified as CWE-787. The lack of proper validation of user-supplied data causes the application to write past the end of an allocated buffer. This overflow can be exploited to execute arbitrary code in the context of the current process, giving an attacker full control of the affected system.
Affected Systems
The vulnerability affects OriginLab OriginPro. No specific version information is available, so any installation of OriginPro that has not received the vendor’s fix is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score is not available and the issue is not listed in CISA KEV, but the vulnerability requires user interaction: the target must open a malicious OPJU file or visit a malicious page. This makes exploitation possible but not purely passive, and the ability to run arbitrary code indicates a significant risk for confidentiality, integrity, and availability if the attacker gains control of the process.
OpenCVE Enrichment