First published: Fri Feb 10 2017(Updated: )
A potential remote code execution vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially crafted PDF file can cause a vulnerability resulting in potential code execution. An attacker can send the victim a specific PDF file to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nitro PDF Pro | <=10.5.9.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8711 is classified as a critical vulnerability due to its potential for remote code execution.
To mitigate CVE-2016-8711, users should update Nitro Pro 10 to the latest version available beyond 10.5.9.9.
CVE-2016-8711 is associated with remote code execution attacks that exploit specially crafted PDF files.
CVE-2016-8711 impacts Nitro Pro 10 versions up to and including 10.5.9.9.
Yes, CVE-2016-8711 can be triggered remotely by sending a malicious PDF file to the victim.