Heap-Based Buffer Overflow Vulnerability in Tungsten Automation Power PDF
CVE-2024-9741

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
22 November 2024

What is CVE-2024-9741?

A heap-based buffer overflow vulnerability exists within the parsing of PDF files in Tungsten Automation Power PDF. The flaw occurs due to insufficient validation of user-supplied data length before copying it to a fixed-length heap-based buffer. Successful exploitation of this vulnerability requires user interaction, as it necessitates the victim to either visit a malicious web page or open a compromised PDF file. This can lead to arbitrary code execution in the context of the current process, potentially compromising the integrity and security of the system.

Affected Version(s)

Power PDF 5.0.0.10.0.23307

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.