← back
CVE-2019-5046

CVE-2019-5046

CVSS 8.8 HIGHEPSS 2.3%CWE-122
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 2.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
09 Oct 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A specifically crafted jpeg2000 file embedded in a PDF file can lead to a heap corruption when opening a PDF document in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would need to open the malicious file.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · NitroPDF

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →