Description
Documalis Free PDF Editor version 5.7.2.26 and Documalis Free PDF Scanner version 5.7.2.122 do not appropriately validate the contents of JPEG images contained within a PDF. Attackers can exploit this vulnerability to trigger a buffer overflow on the stack and gain remote code execution as the user running the Documalis Free PDF Editor or Documalis Free PDF Scanner software.
Exploits (1)
metasploit
WORKING POC
NORMAL
by metacom · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/documalis_pdf_editor_and_scanner.rb
Scores
CVSS v3
5.3
EPSS
0.4409
EPSS Percentile
97.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Details
CWE
CWE-120
Status
published
Products (2)
documalis/free_pdf_editor
5.7.2.26
documalis/free_pdf_scanner
5.7.2.122
Published
Aug 12, 2020
Tracked Since
Feb 18, 2026