PDF-XChange Editor Out-Of-Bounds Read Vulnerability in PRC File Parsing Allowing Information Disclosure

Vulnerability

A vulnerability allowing out-of-bounds read has been identified in PDF-XChange Editor versions 10.5.2.395, 10.5.1.394, 10.5.0.393, 10.4.4.392, 10.4.2.390, 10.4.0.388, 10.1.2.382, 10.1.1.381, 10.0.0.370, and 9.5.368.0. This vulnerability arises from improper validation of user-supplied data when parsing PRC files, leading to reading past the end of an allocated object. As a result, remote attackers can exploit this vulnerability to disclose sensitive information. User interaction is required, as the target must open a malicious PRC file or visit a malicious page.

Impact

Exploitation of this vulnerability can lead to unauthorized information disclosure. Additionally, according to the Zero Day Initiative, this vulnerability could be leveraged, in conjunction with others, to execute arbitrary code within the current process context.

Remediation

PDF-XChange has released a security update to address this vulnerability. Users can download the latest version from the PDF-XChange website or through the PDF-XChange Updater.

Added: Jun 25, 2025, 10:48 PM
Updated: Jun 25, 2025, 10:48 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.