PDF-XChange Editor Out-Of-Bounds Read Vulnerability in PRC File Parsing Allowing Information Disclosure

Vulnerability

A vulnerability allowing out-of-bounds read has been identified in PDF-XChange Editor versions 10.5.2.395 and prior. This issue arises from improper validation of user-supplied data when parsing PRC files, leading to the potential for remote attackers to read past the end of an allocated buffer. Exploitation of this vulnerability requires user interaction, as the target must open a malicious PRC file or visit a page containing one. Additionally, this vulnerability could be leveraged alongside others to execute arbitrary code within the current process context.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure, with the potential for arbitrary code execution in the context of the affected process.

Remediation

Users are advised to update to PDF-XChange Editor version 10.6.0.396, which addresses this vulnerability. Instructions for updating can be found on the PDF-XChange website.

Added: Jun 25, 2025, 10:50 PM
Updated: Jun 25, 2025, 10:50 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.