Kofax Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
CVE-2024-5510

7.8HIGH

Key Information:

Vendor
Kofax
Status
Vendor
CVE Published:
22 November 2024

Summary

A vulnerability exists in Kofax Power PDF related to the parsing of JP2 files, allowing remote attackers to execute arbitrary code under certain conditions. This flaw is caused by inadequate validation of data supplied by users, leading to the potential for reading beyond the bounds of allocated memory. To exploit this vulnerability, users must interact with an attacker-crafted file or visit a malicious webpage, making it imperative for organizations utilizing Kofax Power PDF to implement security measures and apply relevant patches to mitigate risks associated with CVE-2024-5510.

Affected Version(s)

Power PDF 5.0.0.57 (5.0.0.10.0.23307)

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.