PDF-XChange Editor
cpe:2.3:a:pdf-xchange:pdf-xchange_editor:*:*:*:*:*:*:*
- >= 10.0.1.371, <= 10.0.1.371
- >= 9.5.367.0, <= 9.5.367.0
- >= 9.5.366.0, <= 9.5.366.0
- >= 9.4.364.0, <= 9.4.364.0
A vulnerability allowing out-of-bounds read has been identified in PDF-XChange Editor versions 10.5.2.395 and prior. This issue arises from improper validation of user-supplied data when parsing U3D files, leading to the potential for reading past the end of an allocated buffer. As a result, remote attackers could exploit this vulnerability to disclose sensitive information. The vulnerability requires user interaction, as the target must open a malicious U3D file or visit a page containing one.
Exploitation of this vulnerability could lead to unauthorized information disclosure. Additionally, according to the Zero Day Initiative, this vulnerability could be leveraged to execute arbitrary code in the context of the current process.
PDF-XChange has released a security update to address this vulnerability. Users can download the latest version from the PDF-XChange website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.