Power PDF File Parsing Use-After-Free Remote Code Execution Vulnerability
CVE-2023-44435
7.8HIGH
Summary
A vulnerability exists in Kofax Power PDF related to the parsing of PDF files, which can lead to remote code execution. The flaw arises due to the absence of proper validation for object existence before executing operations on it. This allows attackers to craft malicious PDF files that, when opened by the user, can execute arbitrary code in the context of the affected application. Effective exploitation requires user interaction, making it essential for users to be cautious when dealing with suspicious files or links.
Affected Version(s)
Power PDF 5.0.0.57 (5.0.0.10.0.23307)
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved