Impact
The vulnerability is an out-of-bounds write during PDF parsing that can be triggered by specially crafted PDF files. The flaw is captured in CWE-787 and allows a remote attacker to execute arbitrary code in the context of the PDF Architect process once the file is processed. Because the attacker’s code runs with the same privileges as the user running the application, the impact ranges from local escalation to full system compromise.
Affected Systems
Affected software is pdfforge PDF Architect. No specific version information is publicly disclosed, so all installations that are still on older releases may be vulnerable. Users should verify the version they run and check for any available updates from pdfforge.
Risk and Exploitability
The CVSS score of 7.8 indicates high potential impact but user must open a malicious PDF or navigate to a page that serves such a file to the application. EPSS score of < 1% indicates a low likelihood of exploitation and the vulnerability is not in the CISA KEV catalog, but given the remote code execution payload and the lack of a safeguard, the risk remains significant. Attackers would typically employ phishing emails or compromised websites to entice victims into opening the malicious document.
OpenCVE Enrichment