CVE-2025-14402 is a Remote Code Execution vulnerability in PDFsam Enhanced, specifically affecting its processing of DOC files. It allows attackers to execute arbitrary code on a victim's system if they open a malicious DOC file or visit a malicious web page, due to insufficient user warnings before executing dangerous scripts. Rated High severity with a CVSS score of 7.0, this vulnerability requires user interaction and has high impact on confidentiality, integrity, and availability. Currently, there is no public exploit intelligence, Metasploit modules, or community discussion, indicating it is not actively exploited or widely known.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0.76.15222CPE matchmatch criteria | cpe:2.3:a:pdfsam:enhanced:7.0.76.15222:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.