#VU53895 Out-of-bounds read in Paint 3D - CVE-2021-31946
Published: June 8, 2021 / Updated: June 11, 2021
Paint 3D
Microsoft
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary condition when parsing GLB files in Paint 3D. A remote attacker can create a specially crafted GLB file, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system.