CVE-2018-25217

PDF Explorer 1.5.66.2 contains a structured exception handler (SEH) overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH records with malicious data. Attackers can craft a payload with buffer overflow, NSEH jump, and ROP gadget chains that execute when the Custom fields settings dialog processes the malicious input in the Label field.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rttsoftware:pdf_explorer:1.5.66.2:*:*:*:*:*:*:*

History

27 Mar 2026, 18:16

Type Values Removed Values Added
References () http://www.rttsoftware.com/ - () http://www.rttsoftware.com/ - Product
References () https://www.exploit-db.com/exploits/46016 - () https://www.exploit-db.com/exploits/46016 - Exploit, VDB Entry
References () https://www.rttsoftware.com/files/PDFExplorerTrialSetup.zip - () https://www.rttsoftware.com/files/PDFExplorerTrialSetup.zip - Product
References () https://www.vulncheck.com/advisories/pdf-explorer-structured-exception-handler-local-code-execution - () https://www.vulncheck.com/advisories/pdf-explorer-structured-exception-handler-local-code-execution - Third Party Advisory
Summary
  • (es) PDF Explorer 1.5.66.2 contiene una vulnerabilidad de desbordamiento de gestor de excepciones estructurado (SEH) que permite a atacantes locales ejecutar código arbitrario sobrescribiendo registros SEH con datos maliciosos. Los atacantes pueden crear una carga útil con desbordamiento de búfer, salto NSEH y cadenas de gadgets ROP que se ejecutan cuando el diálogo de configuración de campos personalizados procesa la entrada maliciosa en el campo 'Label'.
First Time Rttsoftware pdf Explorer
Rttsoftware
CPE cpe:2.3:a:rttsoftware:pdf_explorer:1.5.66.2:*:*:*:*:*:*:*

26 Mar 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-26 14:16

Updated : 2026-03-27 18:16


NVD link : CVE-2018-25217

Mitre link : CVE-2018-25217

CVE.ORG link : CVE-2018-25217


JSON object : View

Products Affected

rttsoftware

  • pdf_explorer
CWE
CWE-787

Out-of-bounds Write