Impact
The flaw in pdfforge PDF Architect involves an out‑of‑bounds read in the handling of App objects, leading to remote code execution. The vulnerability, classified as CWE‑125, permits an attacker to run arbitrary code in the process context of the user. As a victim into visiting a malicious page or opening a malicious file.
Affected Systems
Affected product is pdfforge PDF Architect. No specific version information is provided, until a patch is applied.
Risk and Exploitability
The CVSS score of high severity. The EPSS score indicates a very low likelihood of exploitation (0.0017), and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction, typically by viewing a crafted web page or opening a malicious PDF. Once executed, the attacker can run code with the privileges of the current process. The lack of input validation is the root cause.
OpenCVE Enrichment