CVE-2020-6094

HIGH

Accusoft ImageGear 19.4-19.6 - Remote Code Execution via TIFF File Parsing

Title source: llm
STIX 2.1

Description

An exploitable code execution vulnerability exists in the TIFF fillinraster function of the igcore19d.dll library of Accusoft ImageGear 19.4, 19.5 and 19.6. A specially crafted TIFF file can cause an out-of-bounds write, resulting in remote code execution. An attacker can provide a malicious file to trigger this vulnerability.

References (1)

Core 1
Core References
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1017

Scores

CVSS v3 8.8
EPSS 0.0360
EPSS Percentile 88.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-190 CWE-787
Status published
Products (3)
accusoft/imagegear 19.4.0
accusoft/imagegear 19.5.0
accusoft/imagegear 19.6.0
Published May 06, 2020
Tracked Since Feb 18, 2026