Impact
A buffer overflow vulnerability exists in PDF Shaper versions 3.5 and 3.6 when the Convert PDF to Image feature processes a specially crafted PDF file. The overflow in the PDFTools.exe component allows an attacker to overwrite memory and execute arbitrary code with the privileges of the user who opens the file.
Affected Systems
The affected product is Burnaware PDF Shaper 3.5 and 3.6, which run on Windows XP, 7, 8 and 10. Any installation of these releases that has the Convert PDF to Image feature enabled is susceptible to the overflow.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, and the EPSS score of 10% suggests a notable likelihood of exploitation. Although the vulnerability is not listed in the CISA KEV catalog, the combination of an easily storyable attack vector—tricking a user into opening a malicious PDF—and the ability to achieve code execution in the user’s context makes this a significant threat to affected systems.
OpenCVE Enrichment
EUVD