#VU27995 Use-after-free in Nitro Pro - CVE-2020-6074

 

#VU27995 Use-after-free in Nitro Pro - CVE-2020-6074

Published: May 19, 2020


Vulnerability identifier: #VU27995
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2020-6074
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Nitro Pro
Software vendor:
Nitro Software, Inc.

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in the PDF parser. A remote attacker can trick a victim to open a specially crafted PDF document and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Remediation

Install updates from vendor's website.

External links