
Cloud Vulnerability DB
A community-led vulnerabilities database
An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155, identified as CVE-2020-6074. The vulnerability was discovered by Cory Duplantis of Cisco Talos and publicly disclosed on May 18, 2020. The flaw affects Nitro Pro PDF reader, a software designed for reading, editing, signing, and saving PDF files (Talos Report, SecurityWeek).
The vulnerability is classified as a Use-After-Free (CWE-416) issue with a CVSS v3.1 base score of 8.8 (HIGH). During PDF parsing, a buffer is allocated for each page and stored in a larger PDF object. In the case of nested pages, it's possible to free this page in the overarching PDF object. While the page is freed, it's never cleared from the original PDF object, allowing a carefully crafted PDF to potentially write an arbitrary null byte out of bounds (Talos Report).
The vulnerability can lead to remote code execution on affected systems. A successful exploitation could allow attackers to execute arbitrary code on the target system, potentially compromising the security of the affected machine. This is particularly concerning given Nitro Software's large enterprise customer base, which includes more than 10,000 organizations (SecurityWeek).
An attacker can exploit this vulnerability by providing a specially crafted PDF document to the victim. The exploitation requires user interaction, as the victim must open the malicious file. The vulnerability can be triggered by crafting a PDF that claims to have more pages than given via the /Kids tag (Talos Report).
Users of Nitro Pro version 13.9.1.155 are advised to update their software to the latest version. The vulnerability was reported to the vendor on February 17, 2020, and a security update addressing this issue was released in early May 2020 (SecurityWeek).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."