Out-Of-Bounds Read Vulnerability in PDF-XChange Editor
CVE-2024-8837

7.8HIGH

Key Information:

Vendor
CVE Published:
22 November 2024

Summary

A vulnerability has been identified in PDF-XChange Editor related to the parsing of XPS files. The flaw arises due to inadequate validation of user-supplied data, which can lead to an out-of-bounds read condition. This vulnerability permits remote attackers to execute arbitrary code on affected installations by enticing users to visit malicious sites or open compromised files. Successful exploitation results in running code within the context of the current process, thus posing a significant risk to users.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.