Out-Of-Bounds Write Vulnerability in Tungsten Automation Power PDF
CVE-2024-9740
7.8HIGH
What is CVE-2024-9740?
The vulnerability arises from improper validation during the parsing of BMP files in Tungsten Automation Power PDF. This flaw can enable remote attackers to execute arbitrary code by leveraging a crafted BMP file. Successful exploitation requires user interaction, as the victim must open the malicious file or visit a specially crafted web page. The consequence of this issue could allow an attacker to manipulate the execution flow of the affected process, leading to unauthorized actions within the system.
Affected Version(s)
Power PDF 5.0.0.10.0.23307
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
CVSS V3.0
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
