CVE-2024-30373
CVE-2024-30373 is a remote code execution vulnerability in Kofax Power PDF due to an out-of-bounds write during JPF file parsing. Exploitation requires user interaction, such as opening a malicious file.
CVE-2024-30373 allows attackers to execute arbitrary code on systems running Kofax Power PDF. The vulnerability stems from insufficient validation of user-supplied data while parsing JPF files, leading to a write beyond allocated memory. While the CVSS score is 7.8, SOCRadar's Vulnerability Risk Score (SVRS) is 30, indicating a lower immediate threat level compared to vulnerabilities with scores above 80. However, the presence of "In The Wild" tags signifies that exploitation attempts have been observed. Successful exploitation grants an attacker the ability to execute code within the context of the current process, potentially leading to complete system compromise. Prioritize patching systems running Kofax Power PDF to mitigate the risk.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.