Remote Code Execution Vulnerability in Tungsten Automation Power PDF
CVE-2024-9732

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
22 November 2024

What is CVE-2024-9732?

The vulnerability within Tungsten Automation Power PDF arises from improper handling of XPS file parsing, specifically a use-after-free error. This flaw permits an attacker to execute arbitrary code on the affected system, provided that the user interacts with a malicious file or webpage. Effective exploitation can lead to serious security incidents as attackers could gain control of the system processes, making it crucial for users to apply mitigations promptly to safeguard their installations.

Affected Version(s)

Power PDF 5.0.0.10.0.23307

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.