CVE-2021-40417 is a critical heap-based buffer overflow vulnerability affecting Blackmagic Design DaVinci Resolve, specifically within its DPDecoder service when processing submitted video files. The vulnerability stems from an integer overflow during heap buffer size calculation, leading to an undersized buffer and subsequent overflow when written to. This flaw carries a CVSS score of 9.8 (Critical) due to its network-exploitable nature, low attack complexity, and potential for complete compromise (code execution). While not currently listed in CISA KEV, there is limited public exploit intelligence, with no Metasploit or ExploitDB modules, but it has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
17.3.1.0005CPE matchmatch criteria | cpe:2.3:a:blackmagicdesign:davinci_resolve:17.3.1.0005:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.