PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
CVE-2023-42063
7.8HIGH
Summary
A remote code execution vulnerability has been identified in PDF-XChange Editor that concerns the improper parsing of U3D files. This flaw originates from insufficient validation of data supplied by users, leading to potential out-of-bounds reads. An attacker could exploit this vulnerability by enticing users to visit a malicious webpage or open a specially crafted file, enabling arbitrary code execution within the context of the affected application. It is crucial for users to apply necessary patches and updates as released by Tracker Software to mitigate potential risks.
Affected Version(s)
PDF-XChange Editor 9.5.368.0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved