Out-Of-Bounds Read Vulnerability in PDF-XChange Editor
CVE-2024-8822
5.5MEDIUM
Summary
A notable vulnerability exists in PDF-XChange Editor, related to the inadequate validation when parsing U3D files. This flaw could permit remote attackers to gain access to sensitive information on affected systems. User interaction is necessary, as the risk arises when users visit malicious web pages or open compromised files. The vulnerability stems from reading beyond the allocated buffer due to improper handling of user-supplied data, potentially allowing attackers to exploit this in conjunction with other vulnerabilities to execute arbitrary code within the application's running context.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published