CVE-2026-92180: pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the activation-service process. The product loads a library from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. Was ZDI-CAN-29536.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Affected PDF Architect installations are exposed when an attacker can already execute code locally with low privileges. This is a local privilege-escalation issue, so it is not described as remotely exploitable from the provided information.
What access does an attacker need to exploit this issue?
The attacker must first obtain the ability to execute low-privileged code on the target system. They can then exploit an unsecured library search location used by the activation-service process.
What is the potential impact of a successful exploit?
A successful exploit can allow the attacker to escalate privileges and execute code in the context of SYSTEM. The provided severity vector indicates high impact to confidentiality, integrity, and availability.