ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-615: (0Day) pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

lowVulnerabilityimportance 22
AI summary · glm-5.3-flash

Zero Day Initiative disclosed an uncontrolled search path flaw in pdfforge PDF Architect's update service, allowing local privilege escalation (CVSS 7.8).

ZDI published advisory ZDI-26-615 describing a local privilege escalation vulnerability in the activation-service Update Service of pdfforge PDF Architect. An uncontrolled search path element lets local attackers escalate privileges, but they must first be able to execute low-privileged code on the target. ZDI rated the issue 7.8 and tagged it as a 0-day disclosure.

  • Uncontrolled search path element in the activation-service Update Service enables local privilege escalation
  • Attacker needs prior low-privileged code execution on the system
  • ZDI assigned CVSS 7.8 and flagged the issue as a 0-day
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.

This source does not provide full text. Read it at zerodayinitiative.com.