Polarisoffice produces a productivity and reporting software line with a narrow but engaged user base, encompassing products such as Polaris Office, Polaris ML Report, and Polaris Office 2017. The observed vulnerability surface centers on memory-safety issues—including uninitialized pointers, divide-by-zero conditions, out-of-bounds writes, stack-based buffer overflows, and untrusted search path handling—that reflect the low-level implementation challenges common to client-side office applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Polarisoffice over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12589HIGH Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in the current working directory. | Jun 28, 2018 | 7.8 | 46 | NO | YES |
CVE-2020-7837HIGH An issue was discovered in ML Report Program. There is a stack-based buffer overflow in function sub_41EAF0 at MLReportDeamon.exe. The function will call vsprintf without checking | Dec 16, 2020 | 8.8 | 25 | NO | NO |
CVE-2021-34280HIGH Polaris Office v9.103.83.44230 is affected by a Uninitialized Pointer Vulnerability in PolarisOffice.exe and EngineDLL.dll that may cause a Remote Code Execution. To exploit the vu | Jun 8, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-27550MEDIUM Polaris Office v9.102.66 is affected by a divide-by-zero error in PolarisOffice.exe and EngineDLL.dll that may cause a local denial of service. To exploit the vulnerability, someon | Feb 23, 2021 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Polarisoffice.
Media articles that mention a CVE ID that affects a product developed by Polarisoffice — matched by CVE ID, not by vendor name.