PDF-XChange Editor Out-Of-Bounds Read Vulnerability in PRC File Parsing Allows Information Disclosure

Vulnerability

A vulnerability allowing out-of-bounds read has been identified in PDF-XChange Editor versions 10.5.2.395 and prior. This issue arises from improper validation of user-supplied data when parsing PRC files, leading to the potential for reading past the end of an allocated object. As a result, remote attackers could exploit this vulnerability to disclose sensitive information. Furthermore, this out-of-bounds read could be leveraged in conjunction with other vulnerabilities to execute arbitrary code within the context of the current process.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure. Additionally, according to the Zero Day Initiative, this vulnerability could be combined with others to execute arbitrary code.

Remediation

PDF-XChange has released a security update to address this vulnerability. Users can download the latest version from the PDF-XChange website.

Added: Jun 25, 2025, 10:28 PM
Updated: Jun 25, 2025, 10:28 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.