PT-2026-7164 · Unknown · Sumatrapdf

Mariorl0

·

Published

2026-02-09

·

Updated

2026-02-10

·

CVE-2026-25880

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SumatraPDF versions prior to 3.5.3
Description SumatraPDF, a multi-format reader for Windows, allows execution of a malicious binary, specifically explorer.exe, located in the same directory as an opened PDF file. This occurs when a user clicks File → “Show in folder”. This behavior can lead to arbitrary code execution on the victim’s system with the privileges of the current user, requiring only a menu click for exploitation.
Recommendations Update SumatraPDF to version 3.5.3 or later.

Exploit

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05050
CVE-2026-25880
GHSA-5X4H-247Q-PX37

Affected Products

Sumatrapdf