CVE-2025-14403

7.8

PDFsam · Enhanced

PDFsam Enhanced suffers from an insufficient UI warning vulnerability in the Launch action, which allows attackers to achieve remote code execution via malicious files or web pages.

Executive summary

A critical remote code execution vulnerability in PDFsam Enhanced allows attackers to execute arbitrary code on the host system if a user interacts with a malicious file or page.

Vulnerability

The application fails to issue appropriate warnings when executing dangerous scripts through the Launch action. This flaw allows an unauthenticated attacker to execute code in the context of the current user, provided the user interacts with a malicious file or visits a compromised webpage.

Business impact

Successful exploitation of this vulnerability grants an attacker the ability to execute arbitrary code on the victim's machine. Given the CVSS score of 7.8, this poses a high risk of total system compromise, including data exfiltration, unauthorized access to sensitive files, and potential movement within the local network.

Remediation

Immediate Action: Users should update PDFsam Enhanced to the latest available version provided by the vendor to resolve the unsafe Launch action behavior.

Proactive Monitoring: Security teams should monitor endpoint logs for suspicious process execution patterns originating from PDFsam Enhanced.

Compensating Controls: Restrict users from opening unsolicited PDF files from untrusted sources and utilize endpoint protection software to detect and block malicious script execution.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The vulnerability represents a significant security risk due to the potential for full system compromise. Organizations running the affected version of PDFsam Enhanced must prioritize updating their installations. If an update cannot be applied immediately, ensure that users are trained to avoid opening untrusted PDF documents and maintain strict endpoint security controls to mitigate the risk of code execution.

More PDFsam CVEs

Sources