CVE-2017-13056

Description

The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.997

Associated Vulnerability

VulnerabilityOS Platform
Upgrade PDF-Xchange viewer (x64) 2.5 to latest versionWindows
Upgrade pdf-xchange_viewer 2.5 to latest versionWindows
Vulnerabilities CVE-2017-13056,CVE-2018-18689 are affected in DF-XChange Viewer 2.5Windows
Vulnerabilities CVE-2017-13056,CVE-2018-18689 are affected in PDF-XChange Viewer (x64) 2.5Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-308702PDF-XChange Viewer (x64) (2.5.322.10)
PATCH-308701PDF-XChange Viewer (2.5.322.10)
PATCH-308701PDF-XChange Viewer (2.5.322.10)
PATCH-308702PDF-XChange Viewer (x64) (2.5.322.10)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234