#VU53896 Out-of-bounds read in Paint 3D - CVE-2021-31945
Published: June 8, 2021 / Updated: June 11, 2021
Paint 3D
Microsoft
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary condition when processing GLB files in Paint 3D. A remote attacker can create a specially crafted GLB file, trick the victim into opening it, trigger out-of-bounds read error and execute arbitrary code on the system.