PDF-XChange Editor
cpe:2.3:a:pdf-xchange:pdf-xchange_editor:*:*:*:*:*:*:*
- >= 10.0.1.371, <= 10.0.1.371
- >= 9.5.367.0, <= 9.5.367.0
- >= 9.5.366.0, <= 9.5.366.0
- >= 9.4.364.0, <= 9.4.364.0
A vulnerability allowing out-of-bounds read has been identified in PDF-XChange Editor, specifically in versions through 10.5.2.395. This issue arises during the parsing of U3D files, where improper validation of user-supplied data can lead to reading past the end of an allocated object. As a result, remote attackers could exploit this vulnerability to disclose sensitive information. Additionally, this flaw could be leveraged, in conjunction with other vulnerabilities, to execute arbitrary code within the context of the current process. Exploitation requires user interaction, as the target must open a malicious U3D file or visit a page containing one.
Exploitation of this vulnerability could lead to unauthorized information disclosure and potentially allow for arbitrary code execution, according to the Zero Day Initiative.
Users are advised to update to PDF-XChange Editor version 10.6.0.396 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.