Out-Of-Bounds Read Vulnerability in Tungsten Automation Power PDF
CVE-2024-9751
7.8HIGH
What is CVE-2024-9751?
A vulnerability has been identified in Tungsten Automation Power PDF, specifically related to the parsing of JP2 files. This flaw can allow remote attackers to execute arbitrary code on installations of the software. The issue stems from inadequate validation of user-supplied data, leading to the potential for reading beyond the boundaries of allocated objects. Successful exploitation of this vulnerability requires user interaction, as it necessitates the target to either visit a malicious web page or open a malicious file, thus putting users at risk if they engage with such content.
Affected Version(s)
Power PDF 5.0.0.10.0.23307
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
CVSS V3.0
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
