CVE-2025-15569: Artifex MuPDF win_main.c get_system_dpi uncontrolled search path
A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function getsystemdpi of the file platform/x11/winmain.c. This manipulation causes uncontrolled search path. The attack requires local access. The attack is considered to have high complexity. The exploitability is regarded as difficult. Upgrading to version 1.26.2 is sufficient to resolve this issue. Patch name: ebb125334eb007d64e579204af3c264aadf2e244. Upgrading the affected component is recommended.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15569?
The severity of CVE-2025-15569 is considered high due to the potential for unauthorized local access.
How do I fix CVE-2025-15569?
To address CVE-2025-15569, upgrade to the latest version of Artifex MuPDF that mitigates this uncontrolled search path issue.
What causes CVE-2025-15569?
CVE-2025-15569 is caused by an uncontrolled search path in the get_system_dpi function within Artifex MuPDF.
Who is affected by CVE-2025-15569?
CVE-2025-15569 affects users of Artifex MuPDF version up to 1.26.1 on Windows.
Is local access required to exploit CVE-2025-15569?
Yes, local access is required to exploit the vulnerability in CVE-2025-15569.