CVE-2021-26623

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
01/04/2022
Last modified:
08/04/2022

Description

A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter length value in the ark library. Remote attackers can induce exploit malicious code using this function.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bandisoft:bandizip:*:*:*:*:*:*:*:* 7.19 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*