Unidocs ezPDF DRM Reader and ezPDF Reader Uncontrolled Search Path Vulnerability

Vulnerability

A vulnerability exists in Unidocs ezPDF DRM Reader and ezPDF Reader versions 2.0 and 3.0.0.4 on 32-bit systems. The issue arises from an uncontrolled search path in the SHFOLDER.dll library, allowing local attackers to manipulate DLL loading. This vulnerability is complex to exploit but has a publicly available proof-of-concept exploit.

Impact

Exploitation of this vulnerability allows for local privilege escalation by hijacking the DLL search order. Malicious code can be executed with administrative rights, potentially leading to arbitrary code execution in a high-integrity process.

Reproduction

To reproduce this vulnerability, create a malicious DLL named SHFOLDER.dll and place it in the same directory as the ezPDF DRM Reader or ezPDF Reader installer. When the installer is executed with administrative privileges, the malicious DLL is loaded, and the embedded code is executed with high integrity. This process can be verified using tools like Process Monitor.

Remediation

Unidocs should be contacted for a patch. In the meantime, users can be advised to avoid using the affected versions of the software.

Added: Feb 15, 2026, 1:22 PM
Updated: Feb 15, 2026, 1:22 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
10.0
exploitability
3.8
remediation
0.0
relevance
3.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.