SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-7264

The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign errors, allowing a remote attacker to execute arbitrary code on vulnerable applications using the ActivePDF…

CRITICAL 9.8EPSS 12.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 12.3%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign errors, allowing a remote attacker to execute arbitrary code on vulnerable applications using the ActivePDF Toolkit to process untrusted images.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
12.31% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-787
Affected
activepdf/activepdf toolkit
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.