PT-2026-7172 · Unknown · Sumatrapdf

Haaeein

·

Publicado

2026-02-09

·

Atualizado

2026-02-10

·

CVE-2026-25961

CVSS v2.0

7.6

Alta

VetorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SumatraPDF versions 3.5.0 through 3.5.2
Description SumatraPDF’s update process has a flaw where TLS hostname verification is disabled (INTERNET FLAG IGNORE CERT CN INVALID) and installers are executed without signature verification. This allows a network attacker possessing a valid TLS certificate, such as one from Let's Encrypt, to intercept the update check, inject a malicious installer URL, and potentially execute arbitrary code.
Recommendations Update to a version beyond 3.5.2.

Exploit

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-01951
CVE-2026-25961
GHSA-XPM2-RR5M-X96Q

Produtos afetados

Sumatrapdf