CVE-2020-10223
Nitro Pro vulnerability analysis and mitigation

Overview

CVE-2020-10223 affects Nitro Pro versions before 13.13.2.242. The vulnerability is specifically located in the npdf.dll component and involves a JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at the function npdf!CAPPDAnnotHandlerUtils::create_popup_for_markup+0x12fbe. The vulnerability can be triggered via a specially crafted PDF document (CVE List).

Technical details

The vulnerability is a heap corruption issue that occurs in the JBIG2Decode stream handling functionality within the npdf.dll component of Nitro Pro. The specific vulnerability point is located at the function npdf!CAPPDAnnotHandlerUtils::create_popup_for_markup+0x12fbe (CVE List).

Impact

When successfully exploited, this heap corruption vulnerability could potentially lead to arbitrary code execution in the context of the application, compromising the security of the affected system (CVE List).

Mitigation and workarounds

Users should upgrade their Nitro Pro installation to version 13.13.2.242 or later to address this vulnerability (CVE List).

Additional resources


SourceThis report was generated using AI

Related Nitro Pro vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-35288HIGH7.8
  • Nitro ProNitro Pro
  • cpe:2.3:a:gonitro:nitro_pdf_pro
NoYesOct 09, 2024
CVE-2021-21797HIGH7.8
  • Nitro ProNitro Pro
  • cpe:2.3:a:gonitro:nitro_pro
NoYesOct 18, 2021
CVE-2021-21796HIGH7.8
  • Nitro ProNitro Pro
  • cpe:2.3:a:gonitro:nitro_pro
NoYesOct 18, 2021
CVE-2021-21798HIGH7.8
  • Nitro ProNitro Pro
  • cpe:2.3:a:gonitro:nitro_pro
NoYesSep 15, 2021
CVE-2018-18689MEDIUM5.3
  • Foxit PDF ReaderFoxit PDF Reader
  • cpe:2.3:a:pdf-xchange:pdf-xchange_editor
NoYesJan 07, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management