PT-2026-64165 · Victor · Victor
CVE-2026-21655
·
Published
2026-07-23
·
Updated
2026-08-06
CVSS v4.0
8.7
High
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
victor versions 2.9 through 2.9
Description
An issue exists in the Windows version of the software where the deserialization of untrusted data allows for CAPEC-586, which refers to the process of converting data from a stream or file back into an object in a way that can be manipulated by an attacker to execute unauthorized code or actions.
Recommendations
Update victor to version 3.0.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Victor