PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

CVE Details

Basic Information

Title PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Type cve
Published 2025-06-25T21:42:44.598Z
Last Seen

Product Information

Vendor PDF-XChange
Product PDF-XChange Editor
Version 10.5.2.395

CVSS Information

Base Score 0.0 ()
Attack Vector
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description This vulnerability in PDF-XChange Editor allows attackers to disclose sensitive information by exploiting an out-of-bounds read in U3D file parsing. It requires user interaction, such as opening a malicious file.
AI Severity Medium
Vendor PDF-XChange
Product PDF-XChange Editor
Affected Version 10.5.2.395

Affected Products

  • PDF-XChange PDF-XChange Editor 10.5.2.395

Additional Information

CVE List
CWE List CWE-125
Bulletin Family

Description

PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the parsing of U3D files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-26712.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.