AI analysis
OriginLab OriginPro contains a memory corruption flaw (CWE-119) in its parsing of OGG files, caused by insufficient validation of user-supplied data. An attacker exploits it by convincing a user to open a malicious OGG file (or, per the advisory, visit a malicious page), which triggers the memory corruption and allows execution of arbitrary code in the context of the current process. Any installation of OriginPro whose users open OGG data files from untrusted sources is potentially affected; the available data does not specify affected version ranges. Exploitation is not currently observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only ~0.2% probability of exploitation within 30 days. The vulnerability was disclosed through Trend Micro ZDI (ZDI-CAN-29335, advisory ZDI-26-551).
What to do: Check advisory ZDI-26-551 and OriginLab's release notes for the fixed OriginPro version and upgrade promptly, as fixed-version details are not included in the available data. Until patched, do not open OGG files from untrusted sources in OriginPro and brief users who routinely exchange lab data files. No KEV listing or public PoC exists yet, so treat this as a watch-list item and re-check EPSS/KEV status for changes.
Estimated exposure
moderate≈ tens of thousands of licensed desktop users worldwide (estimate; no public install counts available) — OriginPro is niche, seat-licensed desktop scientific graphing software deployed mainly in academic and industrial research labs, so the affected population is estimated from typical deployment patterns of comparable scientific packages…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro . User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29335.