Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-6074
Nitro Pro vulnerability analysis and mitigation

Overview

An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155, identified as CVE-2020-6074. The vulnerability was discovered by Cory Duplantis of Cisco Talos and publicly disclosed on May 18, 2020. The flaw affects Nitro Pro PDF reader, a software designed for reading, editing, signing, and saving PDF files (Talos Report, SecurityWeek).

Technical details

The vulnerability is classified as a Use-After-Free (CWE-416) issue with a CVSS v3.1 base score of 8.8 (HIGH). During PDF parsing, a buffer is allocated for each page and stored in a larger PDF object. In the case of nested pages, it's possible to free this page in the overarching PDF object. While the page is freed, it's never cleared from the original PDF object, allowing a carefully crafted PDF to potentially write an arbitrary null byte out of bounds (Talos Report).

Impact

The vulnerability can lead to remote code execution on affected systems. A successful exploitation could allow attackers to execute arbitrary code on the target system, potentially compromising the security of the affected machine. This is particularly concerning given Nitro Software's large enterprise customer base, which includes more than 10,000 organizations (SecurityWeek).

Exploitability

An attacker can exploit this vulnerability by providing a specially crafted PDF document to the victim. The exploitation requires user interaction, as the victim must open the malicious file. The vulnerability can be triggered by crafting a PDF that claims to have more pages than given via the /Kids tag (Talos Report).

Mitigation and workarounds

Users of Nitro Pro version 13.9.1.155 are advised to update their software to the latest version. The vulnerability was reported to the vendor on February 17, 2020, and a security update addressing this issue was released in early May 2020 (SecurityWeek).

Additional resources


SourceThis report was generated using AI

Related Nitro Pro vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-69627HIGH8.4
  • Nitro Pro logoNitro Pro
  • cpe:2.3:a:gonitro:nitro_pdf_pro
NoYesApr 13, 2026
CVE-2024-35288HIGH7.8
  • Nitro Pro logoNitro Pro
  • cpe:2.3:a:gonitro:nitro_pdf_pro
NoYesOct 09, 2024
CVE-2025-69624HIGH7.5
  • Nitro Pro logoNitro Pro
  • cpe:2.3:a:gonitro:nitro_pdf_pro
NoYesApr 13, 2026
CVE-2025-66769HIGH7.5
  • Nitro Pro logoNitro Pro
  • cpe:2.3:a:gonitro:nitro_pdf_pro
NoYesApr 13, 2026
CVE-2025-67825MEDIUM5.5
  • Nitro Pro logoNitro Pro
  • cpe:2.3:a:gonitro:nitro_pdf_pro
NoYesJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management