CVE-2018-7264
CRITICALActivePDF Toolkit < 8.1.0.19023 - Remote Code Execution via Pictview Image Processing
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-7264. PoCs published by François Goichon.
AI-analyzed exploit summary The exploit demonstrates multiple remote code execution (RCE) vulnerabilities in ActivePDF Toolkit's embedded Pictview image processing library. It includes proof-of-concept scripts for various image formats (IFF, ZMF, RAS, BPX) that achieve EIP control through out-of-bounds and signedness errors.
Description
The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign errors, allowing a remote attacker to execute arbitrary code on vulnerable applications using the ActivePDF Toolkit to process untrusted images.
Exploits (1)
The exploit demonstrates multiple remote code execution (RCE) vulnerabilities in ActivePDF Toolkit's embedded Pictview image processing library. It includes proof-of-concept scripts for various image formats (IFF, ZMF, RAS, BPX) that achieve EIP control through out-of-bounds and signedness errors.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H