CVE-2012-0897

IrfanView PlugIns <4.33 - RCE

Title source: llm

Description

Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/19519
metasploit WORKING POC NORMAL
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/irfanview_jpeg2000_bof.rb

Scores

EPSS 0.6685
EPSS Percentile 98.6%

Details

CWE
CWE-119
Status published
Products (50)
irfanview/irfanview 1.70
irfanview/irfanview 1.75
irfanview/irfanview 1.80
irfanview/irfanview 1.85
irfanview/irfanview 1.90
irfanview/irfanview 1.95
irfanview/irfanview 1.97
irfanview/irfanview 1.98
irfanview/irfanview 1.98a
irfanview/irfanview 1.99
... and 40 more
Published Jan 20, 2012
Tracked Since Feb 18, 2026