PDFsam Enhanced Out-of-Bounds Read Remote Code Execution Vulnerability
Vulnerability
A remote code execution vulnerability has been identified in PDFsam Enhanced. This issue arises from an out-of-bounds read caused by improper validation of user-supplied data in the handling of App objects. As a result, attackers can read past the end of an allocated buffer, leading to arbitrary code execution in the context of the current process. Exploitation requires user interaction, such as visiting a malicious page or opening a harmful file.
Impact
Exploitation of this vulnerability allows for arbitrary code execution on the affected system.
Remediation
Given the nature of this vulnerability, the recommended mitigation strategy is to limit interaction with the PDFsam Enhanced application.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
