CVE-2023-24308
HIGHPDF-XChange Editor <9.3 - Memory Corruption
Title source: llmDescription
A potential memory vulnerability due to insufficient input validation in PDFXEditCore.x64.dll in PDF-XChange Editor version 9.3 by Tracker Software may allow attackers to execute code when a user opens a crafted PDF file. The issue occurs when handling a large number of objects in a PDF file.
Scores
CVSS v3
7.8
EPSS
0.0004
EPSS Percentile
12.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-755
Status
published
Affected Products (1)
pdf-xchange/pdf-xchange_editor
Timeline
Published
Mar 28, 2023
Tracked Since
Feb 18, 2026