PDF-XChange Editor
cpe:2.3:a:pdf-xchange:pdf-xchange_editor:*:*:*:*:*:*:*
- >= 10.0.1.371, <= 10.0.1.371
- >= 9.5.367.0, <= 9.5.367.0
- >= 9.4.364.0, <= 9.4.364.0
A remote code execution vulnerability has been identified in PDF-XChange Editor versions 10.5.2.395 and prior. This issue arises from improper validation of user-supplied data when parsing U3D files, leading to a write past the end of an allocated object. As a result, remote attackers can execute arbitrary code on affected installations, but exploitation requires user interaction, such as opening a malicious file or visiting a harmful webpage.
Exploitation of this vulnerability allows for arbitrary code execution on the affected system, executed in the context of the current user.
Users are advised to update to PDF-XChange Editor version 10.6.0.396, which addresses this vulnerability. This update can be downloaded from the PDF-XChange website or through the PDF-XChange Updater.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.