CVE-2026-92180
largeUncontrolled Library Search Path in pdfforge PDF Architect Activation Service (SYSTEM LPE)
CVE-2026-92180 is a local privilege escalation vulnerability (CWE-427, uncontrolled search path element) in the activation-service Update Service component of pdfforge PDF Architect on Windows. The activation-service process loads a library from an unsecured, attacker-writable location, so a low-privileged local attacker can plant a malicious DLL that the service loads and executes in the context of SYSTEM. Exploitation requires the attacker to already have the ability to run code on the target machine, such as a standard user account or malware running with limited rights. Anyone running an affected PDF Architect installation on Windows is exposed, since the flaw grants full SYSTEM-level compromise once local code execution is obtained. No public proof of concept is known and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation appears limited to the coordinated disclosure channel (formerly ZDI-CAN-29536).
What to do: Update PDF Architect to the fixed build referenced in the ZDI/pdfforge advisory, since the exact patched version is not stated in this data. As an interim mitigation, use NTFS permissions and application control to block standard users from writing to the PDF Architect installation and service directories, and monitor the activation-service process for DLL loads originating from user-writable paths. Because exploitation requires a local foothold, reinforce least-privilege account policies and treat any successful exploit as full SYSTEM compromise requiring host-level investigation.
| pdfforge PDF Architect | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the activation-service process. The product loads a library from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. Was ZDI-CAN-29536.
- Weakness
- CWE-427
- Vector
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.