- Description
- PDF-XChange Editor RTF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of RTF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25473.
- Source
- zdi-disclosures@trendmicro.com
- NVD status
- Awaiting Analysis
CVSS 3.0
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
- zdi-disclosures@trendmicro.com
- CWE-125
- Hype score
- Not currently trending
🚨 CVE-2025-2231 🔴 HIGH (7.8) 🏢 PDF-XChange - PDF-XChange Editor 🏗️ 10.4.1.389 🔗 https://t.co/t1NHL9RmiR 🔗 https://t.co/PeRG2WpNGw #CyberCron #VulnAlert #InfoSec https://t.co/gCMvkLuEie
@cybercronai
26 Mar 2025
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-2231 03/24/2025 08:15:18 PM BaseSeverity: HIGH PDF-XChange Editor RTF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code ... https://t.co/hcqu8BIXqH
@CVETracker
25 Mar 2025
15 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-2231 PDF-XChange Editor RTF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affe… https://t.co/dSa3UR5CS3
@CVEnew
24 Mar 2025
325 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes