CVE-2022-37367 is a high-severity vulnerability affecting PDF-XChange Editor, allowing remote code execution. It stems from a read past the end of an allocated buffer when handling crafted AcroForms, requiring user interaction to open a malicious file or visit a malicious page. Successful exploitation could lead to arbitrary code execution in the context of the current process. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there's no evidence of active exploitation or significant community discussion, its CVSS score of 7.8 indicates a significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.3.361.0CPE matchmatch criteria | cpe:2.3:a:pdf-xchange:pdf-xchange_editor:9.3.361.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.