Remote Code Execution Vulnerability in PDFsam Enhanced App
CVE-2025-14401

7.8HIGH

Key Information:

Vendor

PDFsam

Status
Vendor
CVE Published:
23 December 2025

What is CVE-2025-14401?

The PDFsam Enhanced App has a vulnerability that permits remote attackers to execute arbitrary code on installations by leveraging an out-of-bounds read condition. This flaw arises from inadequate validation of user-supplied data in handling App objects. While user interaction is necessary, an attacker can exploit this issue by enticing a victim to visit a malicious webpage or open a harmful file. Successful exploitation can lead to code execution in the context of the current process, posing significant risks to users.

Affected Version(s)

Enhanced 7.0.76.15222

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.