Kofax Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2023-42039

7.8HIGH

Key Information:

Vendor
Kofax
Status
Vendor
CVE Published:
3 May 2024

Summary

A buffer overflow vulnerability in Kofax Power PDF has been identified, which arises from improper validation of user-supplied data during PDF file parsing. This vulnerability could be exploited by remote attackers to execute arbitrary code on affected installations, provided that the user interacts with a malicious PDF file or visits a compromised web page. The flaw is tied to the management of fixed-length heap buffers, creating an opportunity for code execution within the context of the current process. Users are advised to update their installations and adhere to security best practices to mitigate the risk associated with this vulnerability.

Affected Version(s)

Power PDF 5.0.0.57 (5.0.0.10)

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.