ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-553: OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability

AI summary · glm-5.3

ZDI discloses OriginLab Origin Viewer OGW file parsing memory corruption RCE (CVE-2026-18294, CVSS 7.8) exploitable via malicious file or page.

ZDI advisory ZDI-26-553 describes a memory corruption vulnerability in OriginLab Origin Viewer's parsing of OGW files, tracked as CVE-2026-18294 with a CVSS score of 7.8. Remote code execution is possible but requires user interaction, meaning the target must open a malicious file or visit a malicious page.

  • OriginLab Origin Viewer OGW file parsing memory corruption
  • CVE-2026-18294 rated CVSS 7.8
  • RCE requires target to open malicious file or visit malicious page

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-18294
Memory Corruption RCE in OriginLab Origin Viewer OGW Parsing

OriginLab Origin Viewer contains a memory-corruption flaw (CWE-119) in its parsing of OGW project files, caused by insufficient validation of user-supplied data. An attacker triggers it by convincing a user to open a malicious OGW file or visit a malicious page, since user interaction is required. Successful exploitation lets the attacker execute arbitrary code in the context of the current process, with the privileges of the user running the viewer. Any installation of OriginLab Origin Viewer is affected; the disclosure does not specify particular version ranges. No public proof-of-concept or in-the-wild exploitation is known, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at a low 0.2%.

Do: Monitor OriginLab and the ZDI-26-553 advisory for a patched Origin Viewer release and update as soon as a fixed build is available; the disclosure data does not name a fixed version. Until patched, only open OGW files from trusted sources and treat unsolicited OGW attachments (e.g., via email) as suspect. Given no known exploitation, no public PoC, and low EPSS, defenders can prioritize this below actively exploited or internet-facing issues.

7.8<1%
  • OriginLab Origin Viewer
unknown
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18294.

This source does not provide full text. Read it at zerodayinitiative.com.