Impact
The flaw resides in pdfforge PDF Architect’s activation-service, which loads a library from an unsecured location. A local attacker who can already execute low‑privileged code can manipulate the library path to drop a malicious DLL. When the service loads this crafted DLL, the attacker obtains SYSTEM privileges, allowing full control over the host. The vulnerability is an uncontrolled search path element, a well‑known source of privilege escalation.
Affected Systems
Any installation of pdfforge PDF Architect that runs the activation-service is vulnerable. Specific product versions are not enumerated in the advisory, so all current releases that include the service on a workstation are considered at risk.
Risk and Exploitability
The CVSS score of 7.8 signals a high severity risk, while an EPSS score of < 1% indicates a very low but nonzero probability of exploitation today. The advisory does not list the issue in the CISA KEV catalog. Exploitation requires a local foothold; the attacker must first achieve low‑privileged code execution before triggering the elevation. Once executed, the flaw grants SYSTEM level control, which represents a critical local threat.
OpenCVE Enrichment