Логотип exploitDog
bind:CVE-2024-27323
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-27323

Количество 3

Количество 3

nvd логотип

CVE-2024-27323

почти 2 года назад

PDF-XChange Editor Updater Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is not required to exploit this vulnerability. The specific flaw exists within the update functionality. The issue results from the lack of proper validation of the certificate presented by the server. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22224.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-6wrg-cr3c-h2hf

почти 2 года назад

PDF-XChange Editor Updater Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is not required to exploit this vulnerability. The specific flaw exists within the update functionality. The issue results from the lack of proper validation of the certificate presented by the server. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22224.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2024-09584

больше 2 лет назад

Уязвимость программы просмотра и редактирования PDF документов PDF-XChange Editor, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-27323

PDF-XChange Editor Updater Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is not required to exploit this vulnerability. The specific flaw exists within the update functionality. The issue results from the lack of proper validation of the certificate presented by the server. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22224.

CVSS3: 7.5
2%
Низкий
почти 2 года назад
github логотип
GHSA-6wrg-cr3c-h2hf

PDF-XChange Editor Updater Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is not required to exploit this vulnerability. The specific flaw exists within the update functionality. The issue results from the lack of proper validation of the certificate presented by the server. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22224.

CVSS3: 7.5
2%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-09584

Уязвимость программы просмотра и редактирования PDF документов PDF-XChange Editor, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.5
2%
Низкий
больше 2 лет назад

Уязвимостей на страницу