CVE-2018-7264
The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign errors, allowing a remote attacker to execute arbitrary code on vulnerable applications using the ActivePDF…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.3%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign errors, allowing a remote attacker to execute arbitrary code on vulnerable applications using the ActivePDF Toolkit to process untrusted images.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 12.31% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- activepdf/activepdf toolkit
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2018/Feb/74Exploit, Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/44251/Exploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Feb/74Exploit, Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/44251/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.