Out-Of-Bounds Read Vulnerability in PDF-XChange Editor by Tracker Software
CVE-2025-0902
What is CVE-2025-0902?
The vulnerability in PDF-XChange Editor arises from improper validation of user-supplied data during the parsing of XPS files. This flaw allows remote attackers to disclose sensitive information by tricking the user into opening a malicious file or visiting a compromised webpage. By exploiting this vulnerability, attackers can potentially read beyond the allocated memory, increasing the risk of further exploiting the affected system. This can lead to arbitrary code execution under the context of the current user, making it crucial for organizations to patch affected installations promptly.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PDF-XChange Editor 10.4.0.388
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
