Impact
The updated description indicates that the vulnerability in MediaInfoLib’s LXF parsing component has been revised, but the specific changes are not included in the data available. Based on the available information, the issue remains a heap-based buffer overflow that can be triggered by a specially crafted .lxf file, potentially leading to arbitrary code execution. The flaw stems from improper bounds checking (CWE‑191) and could compromise confidentiality, integrity, and availability if an attacker supplies malicious content.
Affected Systems
The affected product is MediaArea MediaInfoLib. The known affected version is 26.01, and any installation that uses the LXF parsing component may be vulnerable until a patch becomes available.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating high severity. The EPSS score is < 1%, and it is not listed in CISA's KEV catalog. The attack vector is inferred to be the execution of a malicious LXF file, either through local file modification or external file injection into an application that processes LXF data. No public exploit has been disclosed as of the information provided.
OpenCVE Enrichment