Heap-Based Buffer Overflow Vulnerability in Tungsten Automation Power PDF
CVE-2024-9741
7.8HIGH
What is CVE-2024-9741?
A heap-based buffer overflow vulnerability exists within the parsing of PDF files in Tungsten Automation Power PDF. The flaw occurs due to insufficient validation of user-supplied data length before copying it to a fixed-length heap-based buffer. Successful exploitation of this vulnerability requires user interaction, as it necessitates the victim to either visit a malicious web page or open a compromised PDF file. This can lead to arbitrary code execution in the context of the current process, potentially compromising the integrity and security of the system.
Affected Version(s)
Power PDF 5.0.0.10.0.23307
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
CVSS V3.0
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
