Description
pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the activation-service process. The product loads a library from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. Was ZDI-CAN-29536.
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The flaw resides in pdfforge PDF Architect’s activation-service, which loads a library from an unsecured location. A local attacker who can already execute low‑privileged code can manipulate the library path to drop a malicious DLL. When the service loads this crafted DLL, the attacker obtains SYSTEM privileges, allowing full control over the host. The vulnerability is an uncontrolled search path element, a well‑known source of privilege escalation.

Affected Systems

Any installation of pdfforge PDF Architect that runs the activation-service is vulnerable. Specific product versions are not enumerated in the advisory, so all current releases that include the service on a workstation are considered at risk.

Risk and Exploitability

The CVSS score of 7.8 signals a high severity risk, while an EPSS score of < 1% indicates a very low but nonzero probability of exploitation today. The advisory does not list the issue in the CISA KEV catalog. Exploitation requires a local foothold; the attacker must first achieve low‑privileged code execution before triggering the elevation. Once executed, the flaw grants SYSTEM level control, which represents a critical local threat.

Generated by OpenCVE AI on September 20, 2026 at 14:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest security update from pdfforge that addresses the DLL loading path issue.
  • Restrict file permissions on the activation-service executable directory so that only the SYSTEM account can modify DLL files, preventing low‑privileged users from dropping malicious libraries.
  • Configure Windows policy or adjust the system PATH to block loading of untrusted DLLs in the activation-service directory and enforce a trusted library deployment path.

Generated by OpenCVE AI on September 20, 2026 at 14:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Pdfforge
Pdfforge pdf Architect
Vendors & Products Pdfforge
Pdfforge pdf Architect

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the activation-service process. The product loads a library from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. Was ZDI-CAN-29536.
Title pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Weaknesses CWE-427
References
Metrics cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Pdfforge Pdf Architect
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-09-16T03:57:10.161Z

Reserved: 2026-09-15T18:05:13.202Z

Link: CVE-2026-92180

cve-icon Vulnrichment

Updated: 2026-09-15T19:23:03.488Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T19:17:48.487

Modified: 2026-09-16T20:26:50.280

Link: CVE-2026-92180

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:30:18Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element