CVE-2022-40661 is a heap-based buffer overflow vulnerability in NIKON NIS-Elements Viewer 1.2100.1483.0, specifically within its BMP image parsing functionality. This flaw allows remote attackers to achieve arbitrary code execution if a user opens a malicious BMP file or visits a malicious web page. Rated with a CVSS score of 7.8 (High), this vulnerability requires user interaction (UI:R) and has a low attack complexity (AC:L), but can lead to complete compromise of confidentiality, integrity, and availability (C:H, I:H, A:H). The attacker needs to trick the victim into interacting with malicious content. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed on CISA's KEV catalog. Community discussion and media coverage are also absent, indicating a low level of public awareness or active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2100.1483.0CPE matchmatch criteria | cpe:2.3:a:nikon:nis-elements_viewer:1.2100.1483.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.