CVE-2023-39453: Accusoft Imagegear
Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.
A use-after-free vulnerability exists in the tif_parse_sub_IFD functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can deliver this file to trigger this vulnerability.
Affected products
- Accusoft Imagegear: version 20.1 only
Published 2023-09-25. Last modified 2026-06-17.