← volver
CVE-2026-41511

OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle

CVSS 6.2 MEDIUMEPSS 0.2%CWE-835
OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Storage. Prior to version 3.1.3, OpenMcdf does not detect cycles in the directory entry red-black tree of a Compound File Binary (CFB) document. A crafted CFB file with a cycle in the LeftSiblingID / RightSiblingID chain causes Storage.EnumerateEntries() and Storage.OpenStream() to loop indefinitely, consuming the calling thread with no possibility of recovery via try/catch. This issue has been patched in version 3.1.3.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Productos afectados
ironfede · openmcdf

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →