Kofax Power PDF TGA File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
CVE-2024-5304

7.8HIGH

Key Information:

Vendor
Kofax
Status
Vendor
CVE Published:
6 June 2024

Summary

A vulnerability in Kofax Power PDF allows remote code execution due to improper handling of TGA file parsing. The flaw arises from a lack of validation for user-supplied data, enabling attackers to write beyond the allocated buffer. Exploitation requires user interaction, necessitating that the target either visits a malicious website or opens a specially crafted file. Successful exploitation can result in arbitrary code execution within the context of the current process, posing significant risks to user security.

Affected Version(s)

Power PDF 5.0.0.57

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.