AI analysis
OriginLab Origin Viewer contains a memory-corruption flaw (CWE-119) in its parsing of OGW project files, caused by insufficient validation of user-supplied data. An attacker triggers it by convincing a user to open a malicious OGW file or visit a malicious page, since user interaction is required. Successful exploitation lets the attacker execute arbitrary code in the context of the current process, with the privileges of the user running the viewer. Any installation of OriginLab Origin Viewer is affected; the disclosure does not specify particular version ranges. No public proof-of-concept or in-the-wild exploitation is known, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at a low 0.2%.
What to do: Monitor OriginLab and the ZDI-26-553 advisory for a patched Origin Viewer release and update as soon as a fixed build is available; the disclosure data does not name a fixed version. Until patched, only open OGW files from trusted sources and treat unsolicited OGW attachments (e.g., via email) as suspect. Given no known exploitation, no public PoC, and low EPSS, defenders can prioritize this below actively exploited or internet-facing issues.
Estimated exposure
unknown — no published install or download counts for this free desktop viewer — OriginLab does not publish install/download figures for the free Origin Viewer, the application is local desktop software with no internet-exposed footprint to measure via public scans, and the disclosure data contains no deployment…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGW files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29338.