CVE-2020-7374
Documalis Free PDF Editor / Free PDF Scanner Stack Based Buffer Overflow
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Attend
PoC disponible → seguir de cerca
CVSS 5.3EPSS 3.1%KEV nãoPoC —Nuclei —Metasploit simPatch —
Ciclo de vida
22 may 2020Exploit Metasploit disponible
12 ago 2020Publicada en NVD
Recomendación: Planificar corrección próxima — ya existe PoC pública.
Documalis Free PDF Editor version 5.7.2.26 and Documalis Free PDF Scanner version 5.7.2.122 do not appropriately validate the contents of JPEG images contained within a PDF. Attackers can exploit this vulnerability to trigger a buffer overflow on the stack and gain remote code execution as the user running the Documalis Free PDF Editor or Documalis Free PDF Scanner software.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →