Information Disclosure Vulnerability in PDF-XChange Editor Products by Tracker Software
CVE-2025-0907
8.8HIGH
What is CVE-2025-0907?
The vulnerability in PDF-XChange Editor relates to improper handling of JB2 file parsing, leading to potential exposure of sensitive user data. Attackers must entice users to open malicious JB2 files or visit compromised web pages, triggering an out-of-bounds read that allows unauthorized information disclosure. This flaw arises from inadequate validation of input parameters, paving the way for further exploitation in conjunction with other vulnerabilities, including the potential for arbitrary code execution within the affected application's context.
Affected Version(s)
PDF-XChange Editor 10.4.0.388