ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-611: (0Day) pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability

mediumAdvisoryimportance 30
AI summary · glm-5.3-flash

ZDI published ZDI-26-611, an unpatched out-of-bounds read in pdfforge PDF Architect App Object enabling remote code execution (CVSS 7.8).

The Zero Day Initiative disclosed ZDI-26-611, an out-of-bounds read vulnerability in the App Object component of pdfforge PDF Architect that can lead to remote code execution. Exploitation requires user interaction, such as visiting a malicious page or opening a malicious file. ZDI rated the issue 7.8 on the CVSS scale and marks it as a 0day pending a vendor patch.

  • Out-of-bounds read in App Object component enables remote code execution
  • User interaction with malicious content is required
  • ZDI CVSS score of 7.8; listed as 0day
Vendorspdfforge
OrganizationsZero Day Initiative
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

This source does not provide full text. Read it at zerodayinitiative.com.