CVE-2021-26605

HIGH EXPLOITED

ezPDFReader 2.0-3.0 - Remote Code Execution via JSON-RPC Input

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-26605 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. This issue occurred when the ezPDF launcher received and executed crafted input values through JSON-RPC communication.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0105
EPSS Percentile 59.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

VulnCheck KEV 2021-10-26
CWE
CWE-20
Status published
Products (1)
unidocs/ezpdfreader 2.0 - 3.0
Published Aug 05, 2021
Tracked Since Feb 18, 2026