Impact
The vulnerability is an out-of-bounds read in the SlimPDFReader executable, triggered by the TeighaDo function when it processes a malicious PDF file. This flaw allows an attacker to read memory beyond the intended buffer and potentially expose sensitive data, representing a remote information disclosure type weakness (CWE-119, CWE-125).
Affected Systems
Investintech SlimPDFReader versions up to 2.0.14 are affected and are no longer supported by the maintainer; the vulnerability targets the PDF File Handler component within SlimPDFReader.exe.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, suggesting limited known exploitation. The attack vector is remote, as an adversary can send a crafted PDF to the user. Although exploitation results in a read rather than code execution, the potential to leak confidential data means the risk should not be ignored, especially in environments where sensitive PDFs are processed.
OpenCVE Enrichment