ZeroHour

CVE-2026-92178

moderate

PDF Parsing Memory Corruption RCE in pdfforge PDF Architect

CVSS 3.0
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-92178 is a memory corruption vulnerability (CWE-119) in how pdfforge PDF Architect parses PDF files, caused by improper validation of user-supplied data during parsing. A remote attacker can exploit it by convincing a target to visit a malicious page or open a specially crafted PDF, after which the attacker executes arbitrary code in the context of the current process, gaining the privileges of the logged-in user. All users of affected PDF Architect installations are potentially at risk, though exploitation requires user interaction, which the CVSS 3.0 score of 7.8 (AV:L/AC:L/PR:N/UI:R) reflects. The flaw was disclosed through Trend Micro's Zero Day Initiative as ZDI-CAN-28916. There is no known public proof of concept and it is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Update PDF Architect to the latest version as soon as pdfforge releases a patch and verify the fixed version against the ZDI advisory for ZDI-CAN-28916. Until patched, instruct users not to open PDF files from untrusted sources or follow links to untrusted pages, and consider blocking PDF attachments from unknown senders at the mail gateway. Since exploitation runs code as the logged-in user, running users without administrator privileges will limit the blast radius.

Affected
pdfforge PDF Architect
Estimated exposure
moderatelikely tens of thousands to low hundreds of thousands of desktop installations — PDF Architect is a Windows desktop PDF editor from pdfforge (maker of the widely distributed PDFCreator) with a free tier, so the installed base is plausibly in the tens of thousands to hundreds of thousands, but it is client software with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28916.

Weakness
CWE-119
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.