ZeroHour

CVE-2026-92180

large

Uncontrolled Library Search Path in pdfforge PDF Architect Activation Service (SYSTEM LPE)

CVSS 3.0
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-92180 is a local privilege escalation vulnerability (CWE-427, uncontrolled search path element) in the activation-service Update Service component of pdfforge PDF Architect on Windows. The activation-service process loads a library from an unsecured, attacker-writable location, so a low-privileged local attacker can plant a malicious DLL that the service loads and executes in the context of SYSTEM. Exploitation requires the attacker to already have the ability to run code on the target machine, such as a standard user account or malware running with limited rights. Anyone running an affected PDF Architect installation on Windows is exposed, since the flaw grants full SYSTEM-level compromise once local code execution is obtained. No public proof of concept is known and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation appears limited to the coordinated disclosure channel (formerly ZDI-CAN-29536).

What to do: Update PDF Architect to the fixed build referenced in the ZDI/pdfforge advisory, since the exact patched version is not stated in this data. As an interim mitigation, use NTFS permissions and application control to block standard users from writing to the PDF Architect installation and service directories, and monitor the activation-service process for DLL loads originating from user-writable paths. Because exploitation requires a local foothold, reinforce least-privilege account policies and treat any successful exploit as full SYSTEM compromise requiring host-level investigation.

Affected
pdfforge PDF Architect
Estimated exposure
large≈ hundreds of thousands of Windows desktop installations (order of magnitude 10^5–10^6) — PDF Architect is a widely downloaded freemium Windows PDF suite distributed globally through pdfforge's site and bundle channels, but pdfforge does not publish active-install counts, so this is an estimate from cumulative download patterns…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the activation-service process. The product loads a library from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. Was ZDI-CAN-29536.

Weakness
CWE-427
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.