Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. CertUtil is run in a conhost.exe window, and there is a mechanism allowing CTRL+o to launch cmd.exe as NT AUTHORITY\SYSTEM.
History

Fri, 22 Nov 2024 12:00:00 +0000

Type Values Removed Values Added
References

Wed, 09 Oct 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Gonitro
Gonitro nitro Pdf Pro
CPEs cpe:2.3:a:gonitro:nitro_pdf_pro:*:*:*:*:*:*:*:*
Vendors & Products Gonitro
Gonitro nitro Pdf Pro
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Oct 2024 04:00:00 +0000

Type Values Removed Values Added
Description Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. CertUtil is run in a conhost.exe window, and there is a mechanism allowing CTRL+o to launch cmd.exe as NT AUTHORITY\SYSTEM.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-10-09T00:00:00

Updated: 2024-10-09T20:23:18.282Z

Reserved: 2024-05-15T00:00:00

Link: CVE-2024-35288

cve-icon Vulnrichment

Updated: 2024-10-09T04:03:25.922Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-09T04:15:08.233

Modified: 2024-11-21T09:20:05.000

Link: CVE-2024-35288

cve-icon Redhat

No data.