Power PDF File Parsing Use-After-Free Remote Code Execution Vulnerability
CVE-2023-44435

7.8HIGH

Key Information:

Vendor
Kofax
Status
Vendor
CVE Published:
3 May 2024

Summary

A vulnerability exists in Kofax Power PDF related to the parsing of PDF files, which can lead to remote code execution. The flaw arises due to the absence of proper validation for object existence before executing operations on it. This allows attackers to craft malicious PDF files that, when opened by the user, can execute arbitrary code in the context of the affected application. Effective exploitation requires user interaction, making it essential for users to be cautious when dealing with suspicious files or links.

Affected Version(s)

Power PDF 5.0.0.57 (5.0.0.10.0.23307)

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.