DaviewIndy 8.98.7 and earlier version contain Use-After-Free vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.
https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35539