CVE-2019-13253
Description
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000385474.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
XnView Classic 2.48 suffers a write access violation when opening a crafted file, enabling denial of service or potential code execution.
Vulnerability
XnView Classic version 2.48 (x86) contains a user-mode write access violation (AV) at offset 0x0000000000385474 in the xnview.exe process. The crash is triggered when the application opens a specially crafted file, as demonstrated by a proof-of-concept crash file named id_000206_00. The vulnerability is reproducible with the provided command line and debugger output [1].
Exploitation
An attacker can exploit this vulnerability by crafting a malicious file that, when opened by a victim using XnView Classic 2.48, causes a write AV. No authentication or special network position is required; only user interaction (opening the file) is needed. The exact file type is not specified but is likely an image format supported by XnView [1].
Impact
Successful exploitation results in a denial of service due to the application crash. Depending on memory layout and control over the written data, it may be possible to escalate to arbitrary code execution, though this has not been demonstrated in the available reference. The crash occurs in user mode, limiting the compromise to the XnView process [1].
Mitigation
As of the publication date (2019-07-04), no official patch or updated version addressing CVE-2019-13253 has been released. Users are advised to avoid opening untrusted files with XnView Classic 2.48 and consider using alternative image viewers until a fix is available. The vendor has not acknowledged the issue [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- XnView/XnView Classicdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/apriorit/pentesting/blob/master/bugs/xnview/0x0000000000385474.mdmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.