CVE-2017-15252 describes a critical vulnerability in IrfanView version 4.44 (32bit) when used with PDF plugin version 4.43, allowing arbitrary code execution or denial of service through a specially crafted PDF file. This vulnerability is rated as High severity (CVSS 7.8), indicating that an attacker could achieve significant impact, including confidentiality, integrity, and availability compromise, with low attack complexity, requiring user interaction to open the malicious file. While no public exploit code or active exploitation has been observed, and community discussion is minimal, organizations using affected versions should prioritize patching to mitigate potential risks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.44CPE matchmatch criteria | cpe:2.3:a:irfanview:irfanview:4.44:*:*:*:*:*:x86:* | ||
4.43CPE matchmatch criteria | cpe:2.3:a:irfanview:pdf:4.43:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.