ZDI-26-122: PDF-XChange Editor TrackerUpdate Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of PDF-XChange Editor. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the TrackerUpdate process. The product loads a library from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of a target user.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of PDF-XChange Editor. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2026-2040.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-122?
The severity of ZDI-26-122 is considered high due to its potential for local privilege escalation.
How do I fix ZDI-26-122?
To fix ZDI-26-122, update PDF-XChange Editor to the latest version provided by Tracker Software.
What types of systems are affected by ZDI-26-122?
ZDI-26-122 affects installations of PDF-XChange Editor on local systems where attackers can run low-privileged code.
Can ZDI-26-122 be exploited remotely?
No, ZDI-26-122 requires an attacker to have local access to exploit the vulnerability.
What is the impact of ZDI-26-122 if exploited?
If successfully exploited, ZDI-26-122 allows attackers to escalate their privileges on the affected system.