Description
OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro . User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the parsing of OGG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29335.
Published: 2026-08-20
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OriginLab OriginPro has a flaw in its OGG file parser that can lead to memory corruption. The vulnerability stems from insufficient validation of data supplied in OGG files, allowing an attacker to craft a malicious file that overwrites memory and causes the application to execute arbitrary code in the context of the user’s process. The potential impact includes loss of confidentiality, integrity, and availability of the affected system, as an attacker could gain full control of the host where OriginPro is running.

Affected Systems

The issue affects OriginLab OriginPro installations. No specific version numbers are listed in the advisory, so all currently supported versions should be considered potentially vulnerable until a vendor‑issued update is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity. The EPSS score is not provided, but the lack of publicly listed exploit code and the necessity for a user to open or view a malicious file suggest a moderate to low exploitation probability in uncontrolled environments. The vulnerability is not listed in the CISA KEV catalog, further implying that widespread exploitation has not yet been reported. The likely attack vector requires an attacker to distribute a malicious OGG file or a web page that prompts the user to open one. Once the file is processed, the memory corruption is triggered, leading to remote code execution.

Generated by OpenCVE AI on August 20, 2026 at 20:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the OriginLab patch or upgrade to the latest supported version of OriginPro.
  • Configure the environment to block or quarantine OGG files from untrusted sources, or disable OGG support if it is not needed for business processes.
  • Monitor user activity for the opening of suspicious OGG files and deploy intrusion detection rules that flag abnormal memory usage patterns within OriginPro applications.

Generated by OpenCVE AI on August 20, 2026 at 20:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro . User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29335.
Title OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability
Weaknesses CWE-119
References
Metrics cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-08-20T16:21:25.421Z

Reserved: 2026-07-29T17:09:18.322Z

Link: CVE-2026-18292

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-20T17:17:25.890

Modified: 2026-08-20T17:17:25.890

Link: CVE-2026-18292

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T20:15:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer