CVE-2021-26237 describes a user mode write access violation in FastStone Image Viewer versions up to 7.5, occurring when the software processes a specially crafted CUR file. This vulnerability carries a CVSS score of 7.8 (High), indicating a significant risk of Denial of Service or potential code execution if an unsuspecting user opens a malicious file. While the attack complexity is low and no authentication is required, user interaction is necessary for exploitation. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or Nuclei, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.5CPE matchmatch criteria | cpe:2.3:a:faststone:image_viewer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.