PDF-XChange Editor App Object Use-After-Free Remote Code Execution Vulnerability

Vulnerability

A use-after-free vulnerability has been identified in PDF-XChange Editor, specifically in versions through 10.5.2.395. This vulnerability allows remote attackers to execute arbitrary code on affected installations. The issue arises from the application's handling of App objects, where the existence of an object is not properly validated before operations are performed. Exploitation of this vulnerability requires user interaction, as the target must open a malicious file or visit a malicious webpage.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected system, with the executed code running in the context of the current process.

Remediation

Users can update to PDF-XChange Editor version 10.6.0.396 or later to address this vulnerability.

Added: Jun 25, 2025, 10:26 PM
Updated: Jun 25, 2025, 10:26 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
7.5
exploitability
4.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.