Information Disclosure Vulnerability in PDF-XChange Editor by Tracker Software
CVE-2025-0908
8.8HIGH
Summary
The vulnerability in PDF-XChange Editor is triggered by improper validation during the parsing of U3D files. This flaw can be exploited by remote attackers to disclose sensitive information, requiring the user to visit a malicious webpage or open a compromised file. By exploiting this vulnerability, attackers could possibly read past the allocated memory buffer, leading to potential exposure of confidential data. This vulnerability can be utilized alongside other vulnerabilities to execute arbitrary code in the context of the affected application.
Affected Version(s)
PDF-XChange Editor 10.4.2.390
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved