CVE-2025-2231
CVSS 3.0 Score 7.8 of 10 (high)
Details
Published Mar 24, 2025
Updated: Mar 27, 2025
CWE ID 125
Summary
CVE-2025-2231 is a remote code execution vulnerability affecting PDF-XChange Editor. This issue arises from an out-of-bounds read in the software's RTF file parsing process, which occurs due to insufficient validation of user-supplied data. A malicious RTF file or webpage can exploit this flaw, requiring user interaction. An attacker can then execute arbitrary code in the context of the current process. The vulnerability, identified as ZDI-CAN-25473, underscores the importance of proper data validation in handling user-supplied files.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.