PDF-XChange Editor Out-of-Bounds Read Vulnerability in U3D File Parsing Allowing Information Disclosure

Vulnerability

A vulnerability allowing out-of-bounds read has been identified in PDF-XChange Editor versions 10.5.2.395 and prior. This issue arises from improper validation of user-supplied data when parsing U3D files, leading to the potential for reading past the end of an allocated buffer. As a result, remote attackers could exploit this vulnerability to disclose sensitive information. The vulnerability requires user interaction, as the target must open a malicious U3D file or visit a page containing one.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure. Additionally, according to the Zero Day Initiative, this vulnerability could be leveraged to execute arbitrary code in the context of the current process.

Remediation

PDF-XChange has released a security update to address this vulnerability. Users can download the latest version from the PDF-XChange website.

Added: Jun 25, 2025, 11:05 PM
Updated: Jun 25, 2025, 11:05 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.