First published: Thu Aug 03 2017(Updated: )
Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nitro PDF Pro | =11.0.3.173 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-7442 is considered critical due to the potential for remote code execution.
To fix CVE-2017-7442, update Nitro Pro to the latest version provided by the vendor as it addresses the vulnerability.
CVE-2017-7442 specifically affects Nitro Pro version 11.0.3.173.
CVE-2017-7442 can be exploited through directory traversal sequences in the saveAs and launchURL calls.
Yes, CVE-2017-7442 allows remote attackers to execute arbitrary code, making it exploitable remotely.