CVE-2017-2791
Last modified
CVE-2017-2791 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. JustSystems Ichitaro 2016 Trial contains a vulnerability that exists when trying to open a specially crafted PowerPoint file. Due to the application incorrectly handling the error case for a function's result, the application will use this result in a pointer calculation for reading file data into. EPSS estimates a 1.15% chance of exploitation in the next 30 days.
Description
JustSystems Ichitaro 2016 Trial contains a vulnerability that exists when trying to open a specially crafted PowerPoint file. Due to the application incorrectly handling the error case for a function's result, the application will use this result in a pointer calculation for reading file data into. Due to this, the application will read data from the file into an invalid address thus corrupting memory. Under the right conditions, this can lead to code execution under the context of the application.
Metrics
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Justsystems | Ichitaro | 2016 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-2791?
How severe is CVE-2017-2791?
How do I fix CVE-2017-2791?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-2785An exploitable buffer overflow exists in the psnotifyd appli…10
- CVE-2017-2786A denial of service vulnerability exists in the psnotifyd ap…7.5
- CVE-2017-2787A buffer overflows exists in the psnotifyd application of th…9
- CVE-2017-2788A buffer overflows exists in the psnotifyd application of th…10
- CVE-2017-2789When copying filedata into a buffer, JustSystems Ichitaro Of…8.8
- CVE-2017-2790When processing a record type of 0x3c from a Workbook stream…8.8
- CVE-2017-2792An exploitable heap corruption vulnerability exists in the i…8.3
- CVE-2017-2793An exploitable heap corruption vulnerability exists in the U…8.3
- CVE-2017-2794An exploitable stack-based buffer overflow vulnerability exi…8.3
- CVE-2017-2795An exploitable heap corruption vulnerability exists in the T…8.3
- CVE-2017-2797An exploitable heap overflow vulnerability exists in the Par…8.3
- CVE-2017-2798An exploitable heap corruption vulnerability exists in the G…8.3
Are you affected by CVE-2017-2791?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
