PT-2017-9754 · Nitro · Nitro Pro
Published
2017-02-10
·
Updated
2022-12-14
·
CVE-2016-8711
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nitro Pro version 10
Description
A potential remote code execution issue exists in the PDF parsing functionality. A specially crafted PDF file can cause this issue, resulting in potential code execution. An attacker can send the victim a specific PDF file to trigger this issue.
Recommendations
For Nitro Pro version 10, consider avoiding the use of the PDF parsing functionality until a patch is available. As a temporary workaround, restrict the opening of PDF files from untrusted sources to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nitro Pro