Information Disclosure Vulnerability in PDF-XChange Editor
CVE-2024-8845
5.5MEDIUM
Summary
The vulnerability in PDF-XChange Editor arises from improper validation during the parsing of PDF files, allowing remote attackers to exploit this flaw. The issue enables attackers to disclose sensitive information through an out-of-bounds read condition triggered by user interaction, such as visiting a malicious website or opening a compromised PDF document. Due to insufficient validation of user-supplied data, this flaw may result in reading data beyond the intended buffer limits, potentially leading to further exploitation opportunities alongside other vulnerabilities.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published