CVE-2019-5050 describes a heap corruption vulnerability in NitroPDF version 12.12.1.522, triggered by opening a specially crafted PDF file. This vulnerability carries a CVSS score of 7.8 (High), indicating that an attacker could achieve arbitrary code execution with careful memory manipulation, requiring user interaction (opening the malicious file) and local access. While no public exploits or Metasploit modules are available, and it's not on the KEV catalog, there has been some community discussion and media coverage regarding potential RCE bugs in Nitro PDF Pro.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.12.1.522CPE matchmatch criteria | cpe:2.3:a:gonitro:nitropdf:12.12.1.522:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.