Security readout for executives and security teams
Plain-English summary
This CVE describes a crash-class memory write access violation in ACDSee Free 1.1.21. The public record does not provide a CVSS score, confirmed business impact, patch status, or active exploitation evidence. Treat it as an exposure-management item for endpoints that still run this old application.
Executive priority
Prioritize confirmation over emergency response. Escalate only if the vulnerable version is deployed broadly, used with untrusted files, or vendor guidance confirms stronger impact than the public CVE record states.
Technical view
The reported issue is a user-mode write access violation at IDE_ACDStd!IEP_SetColorProfile+0x1172b0 in ACDSee Free 1.1.21. Available sources do not define the full attack vector, affected file types, exploitability beyond the access violation, or remediation details.
Likely exposure
Exposure is likely limited to systems with ACDSee Free 1.1.21 installed. The source bundle does not identify broader affected versions, platforms, CPEs, or server-side exposure.
Exploitation context
The CVE is publicly disclosed and has a GitHub reference. It is not listed as CISA KEV in the source bundle, and no cited source here confirms active exploitation or reliable code execution.
Researcher notes
Evidence is thin: the CVE text names one version and a fault location, but no CVSS, CWE, patch, affected range, or exploit status. Further assessment should start with vendor advisories and the linked report.
Mitigation direction
- Inventory endpoints for ACDSee Free 1.1.21.
- Check vendor guidance for fixed or supported replacement versions.
- Remove the application where there is no business need.
- Limit use with untrusted files until remediation guidance is confirmed.
Validation and detection
- Confirm installed ACDSee Free versions through endpoint inventory.
- Review software allowlists for legacy ACDSee Free usage.
- Check whether users can open untrusted files with this application.
- Document whether vendor remediation exists before closing the finding.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2019-13252 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/apriorit/pentesting/blob/master/bugs/acdsee/0x00000000001172b0.mdCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
