Information Disclosure Vulnerability in PDF-XChange Editor
CVE-2024-8844
Summary
A vulnerability has been identified in PDF-XChange Editor that arises from improper validation of user-supplied data during PDF file parsing. This flaw allows remote attackers to potentially disclose sensitive information by enticing victims to interact with a malicious PDF or visit a harmful webpage. Exploitation of this vulnerability necessitates user interaction, as the targeted user must open a crafted PDF file. The lack of validation results in an out-of-bounds read, which can permit attackers to read data beyond the allocated memory space, thereby exposing sensitive information. Attackers may also utilize this vulnerability in conjunction with other weaknesses to execute arbitrary code within the context of the current process.
References
CVSS V3.1
Timeline
Vulnerability published