#VU68045 Untrusted pointer dereference in PDF-XChange Editor - CVE-2022-42396

 

#VU68045 Untrusted pointer dereference in PDF-XChange Editor - CVE-2022-42396

Published: October 8, 2022


Vulnerability identifier: #VU68045
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2022-42396
CWE-ID: CWE-822
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
PDF-XChange Editor
Software vendor:
PDF-XChange

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing XPS files. A remote attacker can create a specially crafted XPS file, trick the victim into opening it using the affected software, trigger an untrusted pointer dereference and execute arbitrary code on the target system.


Remediation

Install updates from vendor's website.

External links