Kofax Power PDF PDF File Parsing Memory Corruption Remote Code Execution Vulnerability
CVE-2023-42037

7.8HIGH

Key Information:

Vendor
Kofax
Status
Vendor
CVE Published:
3 May 2024

Summary

A vulnerability in Kofax Power PDF arises from improper validation of user-supplied data during the parsing of PDF files. This flaw may lead to a memory corruption condition, enabling remote attackers to run arbitrary code on systems where the software is installed. Exploitation requires user interaction, whereby the targeted individual must either visit a malicious website or open a compromised PDF file. Once the malicious payload is executed, the attacker can operate within the context of the affected process, potentially leading to further system compromise.

Affected Version(s)

Power PDF 5.0.0.57 (5.0.0.10)

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.