Executive brief
OriginLab Origin Viewer is a document viewer used to display scientific data and analysis files. A flaw in how it parses OGM files can cause memory corruption, allowing an attacker to execute arbitrary code on a user's computer if they are tricked into opening a malicious file or visiting a malicious webpage. This could lead to complete system compromise.
Technical details
This vulnerability is a memory corruption flaw (CWE-119) resulting from insufficient validation of user-supplied data in the OGM file parser within OriginLab Origin Viewer. The attack vector is local with user interaction required—the target must open a malicious OGM file or visit a webpage hosting one. No authentication or elevated privileges are needed. An attacker can exploit this to achieve arbitrary code execution in the context of the Origin Viewer process. The vulnerability has been fixed in Origin Viewer version 10.4.0.25 and later.
Affected products
- OriginLab Origin Viewer
Timeline
- 2026-04-09: disclosed: Vulnerability reported to vendor
- 2026-08-24: patched: Fixed in Origin Viewer 10.4.0.25
- 2026-08-24: advisory: Coordinated public release of advisory