Information Disclosure Vulnerability in PDF-XChange Editor TIF File Parsing
CVE-2024-8836

5.5MEDIUM

Key Information:

Vendor
CVE Published:
22 November 2024

What is CVE-2024-8836?

A vulnerability exists in the PDF-XChange Editor due to improper handling of TIF file parsing. This flaw stems from inadequate validation of user-supplied input, potentially allowing remote attackers to read past the end of an allocated object. This information disclosure issue necessitates user interaction, as the target must either visit a malicious webpage or open a crafted TIF file to exploit the vulnerability. Attackers may exploit this weakness in conjunction with other vulnerabilities to achieve arbitrary code execution within the context of the affected process. Organizations are advised to update to the latest version of PDF-XChange Editor to mitigate the risk.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.
The Cyber Security Vulnerability Database.