CVE-2019-13257
Description
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x00000000003273aa.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
XnView Classic 2.48 has a user mode write access violation when processing a crafted file, leading to a crash.
Vulnerability
XnView Classic version 2.48 contains a user mode write access violation (AV) starting at address xnview+0x00000000003273aa. The crash occurs when opening a specially crafted file, as demonstrated in the provided debug output [1]. The exact file format and conditions required are not specified, but the vulnerability is triggered by user interaction (opening a file).
Exploitation
An attacker can exploit this vulnerability by crafting a malicious file that triggers the write AV when opened in XnView Classic 2.48. The attacker must convince the user to open the file, e.g., via social engineering. No authentication or special privileges are required; the user only needs to double-click or open the file in the application.
Impact
Successful exploitation results in a user mode write access violation, which typically causes the application to crash (denial of service). Depending on the nature of the write AV, it may potentially be leveraged for arbitrary code execution, but the available reference only confirms a crash [1].
Mitigation
As of the publication date (2019-07-04), no official patch or fixed version has been released for XnView Classic 2.48. Users should avoid opening untrusted files with the application and monitor vendor updates for a fix.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- XnView/XnView Classicdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/apriorit/pentesting/blob/master/bugs/xnview/0x00000000003273aa.mdmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.