Information Disclosure Vulnerability in PDF-XChange Editor
CVE-2024-8828
5.5MEDIUM
Summary
The vulnerability resides in the EMF file parsing mechanism of PDF-XChange Editor, which contains a flaw allowing for potential information disclosure. This arises from insufficient validation of user-input data, enabling an out-of-bounds read where an attacker can access memory locations beyond the allocated object. Successfully exploiting this vulnerability requires user interaction, as the targeted user must visit a malicious webpage or open a harmful file crafted by the attacker. By leveraging this flaw alongside other vulnerabilities, an attacker may execute arbitrary code within the affected process context, leading to further compromise.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published