CVE-2013-10057 is a stack-based buffer overflow in the Synactis PDF In-The-Box ActiveX control (PDF_IN_1.ocx), specifically within the ConnectToSynactis method. This vulnerability allows remote attackers to execute arbitrary code by tricking users into visiting a malicious webpage that instantiates the vulnerable control, as seen in third-party software like Logic Print 2013. The vulnerability carries a CVSS score of 7.5 (HIGH), indicating a critical risk. It can be exploited remotely with low attack complexity, leading to high impact on confidentiality, integrity, and availability. User interaction is required for successful exploitation. While not listed on the KEV catalog, a Metasploit module exists for this vulnerability, confirming exploit code availability. The high EPSS score and significant community discussion (12 mentions) suggest considerable interest and potential for exploitation, despite no active exploitation being reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Synactis | PDF In-The-Box | All Versions ImpactedCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.