CVE-2025-14413
7.8Soda · PDF Desktop
A directory traversal vulnerability in Soda PDF Desktop allows remote attackers to execute arbitrary code via malicious CBZ files.
Executive summary
A directory traversal vulnerability in Soda PDF Desktop enables remote code execution when a user opens a specially crafted CBZ file, posing a significant risk to system integrity.
Vulnerability
The software fails to properly validate user supplied paths during the parsing of CBZ files, leading to a path traversal vulnerability. An unauthenticated attacker can leverage this flaw to achieve remote code execution in the context of the current user, provided the user is enticed to open a malicious file.
Business impact
The exploitation of this vulnerability allows for full code execution, which may result in complete system compromise, unauthorized data access, and the potential for lateral movement within the network. With a CVSS score of 7.8, this flaw represents a high-severity risk that could lead to significant operational disruption and loss of confidentiality or integrity.
Remediation
Immediate Action: Users should immediately contact the vendor or monitor the official support portal for the release of a security patch addressing ZDI-25-1086.
Proactive Monitoring: Security teams should monitor endpoint activity for suspicious file execution patterns originating from PDF processing software and review logs for unusual file system access.
Compensating Controls: Organizations should implement restrictive endpoint policies to prevent the execution of untrusted files and utilize security software capable of detecting malicious archive contents.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for remote code execution, this vulnerability poses a severe threat to end-user workstations. Organizations should prioritize the identification of affected installations and restrict the opening of untrusted or externally sourced CBZ files until a vendor-supplied patch is successfully applied.