Remote Code Execution Vulnerability in PDFsam Enhanced DOC File Processing
CVE-2025-14402

7HIGH

Key Information:

Vendor

PDFsam

Status
Vendor
CVE Published:
23 December 2025

What is CVE-2025-14402?

This vulnerability in PDFsam Enhanced concerning DOC file processing can be exploited by remote attackers to execute arbitrary code. The flaw arises from insufficient user warnings when executing potentially dangerous scripts from DOC files. Attackers can manipulate victims into opening these files or visiting malicious web pages, thereby triggering the exploit in the context of the victim's user session. It highlights the importance of user awareness and the need for robust file handling protocols.

Affected Version(s)

Enhanced 7.0.76.15222

References

CVSS V3.0

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.