Impact
An out‑of‑bounds write in PDF Architect opens a specially crafted PDF document or visits a malicious site that forces the application to parse a received file. The flaw arises from insufficient validation of PDF data, enabling an attacker to overwrite memory and run arbitrary code in the context of the running process.
Affected Systems
The vulnerability affects all installations of pdfforge PDF Architect; no specific product version was disclosed in the advisory.
Risk and Exploitability
The CVSS score of 7.8, and the exploit requires user interaction such as opening a malicious PDF or visiting a site that delivers a malicious file. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. The need for user action still poses a significant risk for environments where users handle PDF files.
OpenCVE Enrichment