Out-Of-Bounds Read Vulnerability in PDF-XChange Editor
CVE-2025-0900
3.3LOW
Summary
A vulnerability in PDF-XChange Editor permits remote attackers to disclose sensitive information due to improper validation of user-supplied data during PDF file parsing. The flaw can lead to a read past the end of an allocated object. To exploit this vulnerability, users must open a malicious PDF file or visit a malicious webpage, facilitating the potential for attackers to execute arbitrary code within the current process context when combined with other vulnerabilities.
Affected Version(s)
PDF-XChange Editor 10.4.0.388
References
CVSS V3.0
Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved