Remote Code Execution Vulnerability in Soda PDF Desktop's Handling of Word Files
CVE-2025-14414
7.8HIGH
What is CVE-2025-14414?
Soda PDF Desktop has a vulnerability in its handling of Word files that allows remote attackers to execute arbitrary code on user systems. This flaw arises from insufficient UI warning mechanisms that authorize the execution of potentially dangerous scripts without adequate user alerts. An attacker can exploit this vulnerability by crafting a malicious web page or file that, when accessed by the user, triggers the execution of the harmful code under the current user context. It is imperative for users to remain vigilant and avoid opening untrusted files.
Affected Version(s)
Desktop 14.0.509.23030
