Impact
OriginLab OriginPro is vulnerable to an out‑of‑bounds write during OGG file parsing. The flaw arises because the application does not properly validate user‑supplied data, which enables a malicious OGG file to corrupt memory beyond a buffer and execute arbitrary code in the context of the current process.
Affected Systems
The vulnerability impacts OriginLab OriginPro on all platforms that include the OGG parser. The CNA list is OriginLab:OriginPro; specific version ranges are not disclosed in the advisory.
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability is classified as high severity. Exploitation requires user interaction, such as opening a malicious file or visiting a page that triggers the parser, indicating that the attack is remote but not purely automated. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog, yet the remote code execution potential warrants immediate action.
OpenCVE Enrichment