PDF-XChange Editor
cpe:2.3:a:pdf-xchange:pdf-xchange_editor:*:*:*:*:*:*:*
- >= 10.0.1.371, <= 10.0.1.371
- >= 9.5.368.0, <= 9.5.368.0
- >= 9.5.367.0, <= 9.5.367.0
- >= 9.5.366.0, <= 9.5.366.0
- >= 9.4.364.0, <= 9.4.364.0
A vulnerability allowing out-of-bounds read has been identified in PDF-XChange Editor versions 10.5.2.395 and prior. This issue arises from improper validation of user-supplied data when parsing U3D files, leading to the potential for reading data past the end of an allocated object. As a result, remote attackers could exploit this vulnerability to disclose sensitive information. Additionally, this flaw could be leveraged in conjunction with other vulnerabilities to execute arbitrary code within the context of the current process.
Exploitation of this vulnerability could lead to unauthorized information disclosure and potentially allow for arbitrary code execution in the context of the affected process.
Users are advised to update to PDF-XChange Editor version 10.6.0.396 or later, which addresses this vulnerability. Instructions for updating can be found on the PDF-XChange website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.