Impact
This flaw is a memory corruption condition triggered during the parsing of PDF files. The absence of proper validation of user‑supplied data allows a remote attacker to execute arbitrary code in the context of the PDF Architect process. The impact is full control over the vulnerable system with the privileges of the current user, which can be abused to compromise data, install malware, or pivot further into the system.
Affected Systems
The affected vendor is pdfforge and the product is PDF Architect. All versions of pdfforge PDF Architect are affected as the advisory does not list any excluded versions. The flaw exists within the PDF file parsing module, and no specific version range is provided.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of < 1% suggests a low probability of active exploitation in the wild. Exfiltration of malicious PDF files or a malicious page can trigger exploitation, requiring user action. The vulnerability is not listed in the CISA KEV catalog. The memory corruption flaw (CWE‑119) allows a remote attacker to execute code in the context of the current user, enabling full system compromise if the user has elevated privileges.
OpenCVE Enrichment