A use-after-free vulnerability exists in the Figure stream parsing functionality of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause memory corruption, resulting in arbitrary code execution. Victim would need to open a malicious file to trigger this vulnerability.
- https://talosintelligence.com/vulnerability_reports/TALOS-2023-1758
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1758
No PoCs found on GitHub currently.