Advisories

PDF Complete 3.5.310.2002 - 'pdfsvc.exe' Unquoted Service Path

Go Back
severity
high
date
Affecting
  • PDF Complete <= 3.5.310.2002

CWE
  • CWE-428 Unquoted Search Path or Element
CVSS
8.5
CVSS V4 Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Credit
Zaira Alquicira
Description
PDF Complete 3.5.310.2002 contains an unquoted service path vulnerability in its pdfsvc.exe service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges.