ZDI-26-615: (0Day) pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Zero Day Initiative disclosed an uncontrolled search path flaw in pdfforge PDF Architect's update service, allowing local privilege escalation (CVSS 7.8).
ZDI published advisory ZDI-26-615 describing a local privilege escalation vulnerability in the activation-service Update Service of pdfforge PDF Architect. An uncontrolled search path element lets local attackers escalate privileges, but they must first be able to execute low-privileged code on the target. ZDI rated the issue 7.8 and tagged it as a 0-day disclosure.
- Uncontrolled search path element in the activation-service Update Service enables local privilege escalation
- Attacker needs prior low-privileged code execution on the system
- ZDI assigned CVSS 7.8 and flagged the issue as a 0-day
This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.
This source does not provide full text. Read it at zerodayinitiative.com.