CVE-2025-14401

7.8

PDFsam · PDFsam Enhanced

A remote code execution vulnerability in PDFsam Enhanced exists due to an out-of-bounds read flaw when processing App objects.

Executive summary

PDFsam Enhanced is vulnerable to remote code execution that can be triggered by a user interacting with a malicious file or page, posing a significant risk to system integrity.

Vulnerability

The vulnerability is an out-of-bounds read error occurring during the parsing of App objects. An attacker can leverage this flaw to execute arbitrary code in the context of the application process, provided the victim is enticed into opening a malicious file or visiting a compromised webpage.

Business impact

The potential for remote code execution represents a critical threat to organizational security, potentially allowing attackers to gain full control over the affected host. Given the CVSS score of 7.8, this vulnerability is categorized as High severity, which could lead to unauthorized data access, malware installation, or persistent system compromise.

Remediation

Immediate Action: Organizations should restrict the opening of untrusted PDF files and monitor for vendor-provided security updates. If an update is released, prioritize its deployment across all workstations running the affected software.

Proactive Monitoring: Security teams should monitor endpoint logs for suspicious process execution chains or unexpected network traffic originating from the PDFsam Enhanced application.

Compensating Controls: Deploy endpoint detection and response (EDR) solutions to identify and block malicious child processes spawned by PDF readers.

Exploitation status

Public Exploit Available: No (the referenced ZDI advisory provides technical detail but does not constitute a functional public exploit).

Analyst recommendation

Given the capability for remote code execution, this vulnerability warrants immediate attention despite the requirement for user interaction. Administrators must track the vendor advisory for patch availability and ensure that users are educated on the risks associated with opening unsolicited or untrusted PDF documents.

More PDFsam CVEs

Sources