IrfanView 4.44 (32bit) with FPX Plugin 4.47 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a “User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000a529.”
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-10924
Reference (s):
- http://www.irfanview.net/main_history.htm
- https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10924