Information Disclosure Vulnerability in PDF-XChange Editor by Tracker Software
CVE-2025-0908
8.8HIGH
What is CVE-2025-0908?
The vulnerability in PDF-XChange Editor is triggered by improper validation during the parsing of U3D files. This flaw can be exploited by remote attackers to disclose sensitive information, requiring the user to visit a malicious webpage or open a compromised file. By exploiting this vulnerability, attackers could possibly read past the allocated memory buffer, leading to potential exposure of confidential data. This vulnerability can be utilized alongside other vulnerabilities to execute arbitrary code in the context of the affected application.
Affected Version(s)
PDF-XChange Editor 10.4.2.390