Remote Code Execution Vulnerability in PDFsam Enhanced by PDFsam
CVE-2025-14404

7HIGH

Key Information:

Vendor

PDFsam

Status
Vendor
CVE Published:
23 December 2025

What is CVE-2025-14404?

A vulnerability found in PDFsam Enhanced involves insufficient user interface warnings during the processing of XLS files. This flaw permits remote attackers to execute arbitrary code on affected systems. Exploitation requires user interaction, necessitating that the target visits a malicious webpage or opens a compromised XLS file. The vulnerability stems from a failure to adequately warn users about the execution of potentially harmful scripts, allowing attackers to execute code in the context of the currently logged-in user.

Affected Version(s)

Enhanced 7.0.76.15222

References

CVSS V3.0

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.