Kofax Power PDF PDF File Parsing Memory Corruption Remote Code Execution Vulnerability
CVE-2023-42037
7.8HIGH
Summary
A vulnerability in Kofax Power PDF arises from improper validation of user-supplied data during the parsing of PDF files. This flaw may lead to a memory corruption condition, enabling remote attackers to run arbitrary code on systems where the software is installed. Exploitation requires user interaction, whereby the targeted individual must either visit a malicious website or open a compromised PDF file. Once the malicious payload is executed, the attacker can operate within the context of the affected process, potentially leading to further system compromise.
Affected Version(s)
Power PDF 5.0.0.57 (5.0.0.10)
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved