Kofax Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2023-42039
7.8HIGH
Summary
A buffer overflow vulnerability in Kofax Power PDF has been identified, which arises from improper validation of user-supplied data during PDF file parsing. This vulnerability could be exploited by remote attackers to execute arbitrary code on affected installations, provided that the user interacts with a malicious PDF file or visits a compromised web page. The flaw is tied to the management of fixed-length heap buffers, creating an opportunity for code execution within the context of the current process. Users are advised to update their installations and adhere to security best practices to mitigate the risk associated with this vulnerability.
Affected Version(s)
Power PDF 5.0.0.57 (5.0.0.10)
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved