Vulnerability record · CVE-2012-0897 · published 20 January 2012
CVE-2012-0897: IrfanView JPEG2000 plugin stack buffer overflow via crafted QCD marker
Irfanview · Irfanview
The JPEG2000 plugin in IrfanView PlugIns before 4.33 has a stack-based buffer overflow triggered by a JP2 file containing a crafted Quantization Default (QCD) marker segment. Opening such a file can corrupt the stack and allow code execution in the context of the user running IrfanView.
Description
Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote code execution via a common file format with a high EPSS score, though exploitation requires user interaction and no KEV listing exists.
What it is
The JPEG2000 plugin in IrfanView PlugIns before 4.33 has a stack-based buffer overflow triggered by a JP2 file containing a crafted Quantization Default (QCD) marker segment. Opening such a file can corrupt the stack and allow code execution in the context of the user running IrfanView.
Impact
An attacker who gets a victim to open a malicious JP2 file can execute arbitrary code with the privileges of the IrfanView process, potentially leading to full system compromise.
Attack surface
Reached remotely by delivering a crafted JP2 file that the user opens in IrfanView; no authentication is required, but user interaction (opening the file) is needed per the AV:N/AC:M/Au:N vector.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged, but EPSS is high (0.522, 98.9th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Update IrfanView PlugIns to version 4.33 or later, which fixes the flaw.
- If immediate patching is not possible, restrict or disable the JPEG2000 plugin and avoid opening untrusted JP2 files.
- Block JP2 attachments at email and web gateways where feasible.
- Train users not to open image files from untrusted sources.
- Monitor vendor advisories for any further updates to the plugin.
Detection
- Hunt for IrfanView processes spawning child processes or making unexpected network connections after opening image files.
- Monitor for crashes or access violations in the IrfanView JPEG2000 plugin module.
- Scan email and file transfer logs for JP2 files delivered from external or untrusted senders.
- Use endpoint detection to flag stack corruption or exploit-like behavior in image viewer processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-0897 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-0897), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.