Local Privilege Escalation Vulnerability in PDFsam Enhanced by PDFsam
CVE-2025-14405

6.6MEDIUM

Key Information:

Vendor

PDFsam

Status
Vendor
CVE Published:
23 December 2025

What is CVE-2025-14405?

A vulnerability in PDFsam Enhanced allows physically present attackers to escalate privileges on impacted installations. This arises from the product's configuration of OpenSSL, leading to the loading of its configuration file from an unsecured location. By exploiting this flaw, an attacker who can mount a malicious drive onto the target system can gain elevated privileges and execute arbitrary code as SYSTEM, posing significant security risks.

Affected Version(s)

Enhanced 7.0.76.15222

References

CVSS V3.0

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.