Stack-Based Buffer Overflow in Investintech SlimPDFReader
CVE-2026-8733
Key Information:
- Vendor
Investintech
- Status
- Vendor
- CVE Published:
- 17 May 2026
Badges
What is CVE-2026-8733?
A stack-based buffer overflow vulnerability exists in Investintech SlimPDFReader versions up to 2.0.13, specifically within the function sub_3B4610 of the SlimPDFReader.exe file. This vulnerability allows for remote exploitation, putting users at risk. Despite being made public, the vendor has acknowledged that the product is discontinued and will no longer receive support or updates, leaving existing users vulnerable to potential attacks.
Affected Version(s)
SlimPDFReader 2.0.0
SlimPDFReader 2.0.1
SlimPDFReader 2.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
