PT-2026-7164 · Unknown · Sumatrapdf
Mariorl0
·
Published
2026-02-09
·
Updated
2026-02-10
·
CVE-2026-25880
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SumatraPDF versions prior to 3.5.3
Description
SumatraPDF, a multi-format reader for Windows, allows execution of a malicious binary, specifically
explorer.exe, located in the same directory as an opened PDF file. This occurs when a user clicks File → “Show in folder”. This behavior can lead to arbitrary code execution on the victim’s system with the privileges of the current user, requiring only a menu click for exploitation.Recommendations
Update SumatraPDF to version 3.5.3 or later.
Exploit
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sumatrapdf