ZDI-25-129: PDF-XChange Editor RTF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of RTF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-2231.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ZDI-25-129 - Compensating control
Because exploitation requires user interaction (user must visit a malicious page or open a malicious file), restrict browsing and email/file delivery to reduce the chance users open malicious content (e.g., use web/email filtering to block malicious sites and file types).
- Operational
Ensure users are alerted to avoid opening unsolicited or suspicious files (including RTF documents) and visiting links from untrusted sources.
Event History
Frequently Asked Questions
What is the severity of ZDI-25-129?
The vulnerability ZDI-25-129 has a critical severity rating, indicating it poses a significant risk to affected installations.
How do I fix ZDI-25-129?
To remediate ZDI-25-129, update to the latest version of PDF-XChange Editor provided by Tracker Software.
What type of attack does ZDI-25-129 facilitate?
ZDI-25-129 allows remote attackers to execute arbitrary code on the targeted system.
Is user interaction required to exploit ZDI-25-129?
Yes, user interaction is required as the victim must visit a malicious page or open a harmful file for ZDI-25-129 to be exploited.
Who is affected by ZDI-25-129?
Users of PDF-XChange Editor are vulnerable to the effects of ZDI-25-129 if they do not apply the necessary updates.