Impact
OriginLab Origin Viewer is vulnerable to an out‑of‑bounds write that can be triggered when the software parses OGWU files. The flaw arises because the parser does not properly validate user data, allowing a write beyond the limits of an allocated structure. An attacker can exploit this flaw to execute arbitrary code in the context of the OGV process, which is a high‑impact vulnerability identified as CWE‑787.
Affected Systems
This issue affects installations of OriginLab Origin Viewer. No specific version numbers are provided, so any deployment that has not applied the vendor’s latest patch is potentially impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates substantial risk. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, the lack of a publicly available exploit does not diminish the potential for malicious use. Remote exploitation requires user interaction; an attacker must coerce the victim into opening a malicious OGWU file or visiting a compromised browser page that delivers such a file. Once the file is processed, code execution occurs under the credentials of the current process.
OpenCVE Enrichment