CVE-2026-92177
largeOut-of-Bounds Write RCE in pdfforge PDF Architect PDF Parsing
CVE-2026-92177 is an out-of-bounds write (CWE-787) in the PDF parsing code of pdfforge PDF Architect, a Windows desktop PDF editor, caused by lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. A remote attacker can leverage this to execute arbitrary code in the context of the current process, but user interaction is required: the victim must open a malicious PDF file or visit a malicious page that delivers the crafted document to the application. Successful exploitation gives the attacker code execution with the privileges of the logged-on user, effectively compromising the workstation and any data accessible to that account. The flaw was disclosed through Trend Micro's Zero Day Initiative (ZDI-CAN-28673); there is no known public proof of concept, no evidence of in-the-wild exploitation, and it is not listed in the CISA Known Exploited Vulnerabilities catalog.
What to do: Update PDF Architect to the latest available release and verify the fixed version against the pdfforge and ZDI advisories, since exact affected ranges were not stated in the disclosure data. In the meantime, treat PDFs from untrusted sources as hostile: open them only in a sandboxed/disposable environment and disable browsers from automatically opening downloaded PDFs. Run users with standard (non-admin) privileges and monitor for suspicious child processes or crash behavior originating from PDF Architect.
| pdfforge PDF Architect | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28673.
- Weakness
- CWE-787
- Vector
- CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.