CVE-2020-6064 is an out-of-bounds write vulnerability in the uncompress_scan_line function of Accusoft ImageGear 19.5.0, specifically within its igcore19d.dll library. This flaw allows remote code execution when a specially crafted PCX file is processed, requiring user interaction to trigger. With a CVSS score of 8.8 (High), it presents a significant risk, enabling full compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and it is not on the KEV catalog, its high severity warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
19.5.0CPE matchmatch criteria | cpe:2.3:a:accusoft:imagegear:19.5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.