Information Disclosure Vulnerability in PDF-XChange Editor
CVE-2024-8834

5.5MEDIUM

Key Information:

Vendor
CVE Published:
22 November 2024

Summary

An information disclosure vulnerability exists in PDF-XChange Editor that impacts the parsing of TIF files. This flaw arises from inadequate validation of user-supplied data, allowing remote attackers to read sensitive information beyond the allocated memory space. To exploit this vulnerability, attackers require user interaction, necessitating that victims either visit a malicious webpage or open a malicious TIF file. Successful exploitation may lead to further attacks by leveraging this flaw to execute arbitrary code within the context of the affected process. Vigilance against these manipulative tactics is essential for maintaining security.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.