ZDI-26-614: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
ZDI published ZDI-26-614, another unpatched out-of-bounds write in pdfforge PDF Architect PDF parsing enabling remote code execution (CVSS 7.8).
The Zero Day Initiative published ZDI-26-614, a second out-of-bounds write vulnerability in pdfforge PDF Architect's PDF file parsing. Attackers can execute arbitrary code on affected installations, provided the user visits a malicious page or opens a malicious file. The flaw carries a ZDI-assigned CVSS score of 7.8 and remains unpatched (0day).
- Second out-of-bounds write in PDF parsing enables remote code execution
- Requires user interaction with a malicious page or file
- ZDI CVSS score of 7.8; currently unpatched (0day)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
This source does not provide full text. Read it at zerodayinitiative.com.