PDF Explorer 1.5.66.2 contains a structured exception handler (SEH) overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH records with malicious data. Attackers can craft a payload with buffer overflow, NSEH jump, and ROP gadget chains that execute when the Custom fields settings dialog processes the malicious input in the Label field.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Mar 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:rttsoftware:pdf_explorer:1.5.66.2:*:*:*:*:*:*:* |
Fri, 27 Mar 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rttsoftware
Rttsoftware pdf Explorer |
|
| Vendors & Products |
Rttsoftware
Rttsoftware pdf Explorer |
Thu, 26 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Mar 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PDF Explorer 1.5.66.2 contains a structured exception handler (SEH) overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH records with malicious data. Attackers can craft a payload with buffer overflow, NSEH jump, and ROP gadget chains that execute when the Custom fields settings dialog processes the malicious input in the Label field. | |
| Title | PDF Explorer 1.5.66.2 Structured Exception Handler Local Code Execution | |
| First Time appeared |
Speed Software
Speed Software explorer |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:speed_software:explorer:1.5.66.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Speed Software
Speed Software explorer |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-03-26T13:24:17.314Z
Updated: 2026-03-26T13:57:21.296Z
Reserved: 2026-03-26T13:17:31.692Z
Link: CVE-2018-25217
Updated: 2026-03-26T13:57:17.487Z
Status : Analyzed
Published: 2026-03-26T14:16:05.693
Modified: 2026-03-27T18:16:39.293
Link: CVE-2018-25217
No data.