Executive brief
OriginLab Origin Viewer is a document viewer used to open project files. An out-of-bounds write vulnerability in the parsing of OPJ project files could allow an attacker to execute arbitrary code if a user opens a specially crafted malicious file. Successful exploitation would grant the attacker full control over the affected system with the user's privileges.
Technical details
The vulnerability is an out-of-bounds write flaw in OriginLab Origin Viewer's OPJ file parser. The root cause is insufficient validation of user-supplied data during the parsing of OPJ project files, allowing an attacker to write past the end of an allocated data structure. The attack requires user interaction: a target must open a malicious OPJ file, typically via direct file opening or a deceptive link. An attacker can leverage this memory corruption to achieve arbitrary code execution in the context of the current process. OriginLab has patched this vulnerability; users should update to Origin Viewer 10.4.0.25 or later.
Affected products
- OriginLab Origin Viewer 9.9.5 and earlier
Timeline
- 2026-03-31: disclosed: Vulnerability reported to vendor
- 2026-08-11: advisory: Coordinated public release of advisory (ZDI-26-552)
- 2026-08-20: patched: Fix available in Origin Viewer 10.4.0.25 or later