ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-612: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

mediumAdvisoryimportance 30
AI summary · glm-5.3-flash

ZDI published ZDI-26-612, an unpatched out-of-bounds write in pdfforge PDF Architect PDF parsing enabling remote code execution (CVSS 7.8).

The Zero Day Initiative disclosed ZDI-26-612, an out-of-bounds write vulnerability in pdfforge PDF Architect's PDF file parsing. Successful exploitation allows remote code execution on affected installations. User interaction is required, as the target must visit a malicious page or open a malicious file; ZDI assigned a CVSS score of 7.8 and lists the flaw as a 0day.

  • Out-of-bounds write in PDF file parsing enables remote code execution
  • Requires user interaction with a malicious page or file
  • ZDI CVSS score of 7.8; currently unpatched (0day)
Vendorspdfforge
OrganizationsZero Day Initiative
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

This source does not provide full text. Read it at zerodayinitiative.com.