Remote Code Execution Vulnerability in Kofax Power PDF Allows Attackers to Execute Arbitrary Code
CVE-2024-5306

7.8HIGH

Key Information:

Vendor
Kofax
Status
Vendor
CVE Published:
6 June 2024

Summary

A vulnerability in Kofax Power PDF allows remote attackers to execute arbitrary code by exploiting improper validation during PDF file parsing. This flaw arises due to inadequate checks on user-supplied data, leading to a memory corruption situation. Successful exploitation requires the victim to interact with a malicious webpage or open a compromised PDF file. This poses significant security risks for users of Kofax Power PDF as attackers can execute code within the context of the affected application, potentially leading to unauthorized access and control.

Affected Version(s)

Power PDF 5.0.0.57 (5.0.0.10.0.23307)

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.