Wiz Agents & Workflows are here

CVE-2020-6116
Nitro Pro vulnerability analysis and mitigation

Overview

An arbitrary code execution vulnerability (CVE-2020-6116) exists in the rendering functionality of Nitro Software, Inc.'s Nitro Pro 13.13.2.242 and 13.16.2.300. The vulnerability was discovered in May 2020 and patched in September 2020. When drawing the contents of a page using colors from an indexed colorspace, the application can miscalculate the size of a buffer when allocating space for its colors, leading to potential code execution (Talos Report).

Technical details

The vulnerability occurs in the rendering functionality when processing indexed colorspace data. Due to an integer overflow, the application miscalculates the size of the indexed palette, resulting in an undersized buffer allocation. When loading colors into this buffer, a heap-based buffer overflow occurs. The vulnerability has a CVSSv3 score of 8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is classified as CWE-680 (Integer Overflow to Buffer Overflow) (Talos Report).

Impact

If successfully exploited, this vulnerability can lead to arbitrary code execution under the context of the application. An attacker could potentially gain control of the affected system by having a victim load a specially crafted PDF document (Talos Report).

Mitigation and workarounds

The vulnerability was patched by the vendor on September 1, 2020. Users should upgrade to a version of Nitro Pro released after this date to protect against this vulnerability (Talos Report).

Additional resources


SourceThis report was generated using AI

Related Nitro Pro vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-35288HIGH7.8
  • Nitro ProNitro Pro
  • cpe:2.3:a:gonitro:nitro_pdf_pro
NoYesOct 09, 2024
CVE-2021-21797HIGH7.8
  • Nitro ProNitro Pro
  • cpe:2.3:a:gonitro:nitro_pro
NoYesOct 18, 2021
CVE-2021-21796HIGH7.8
  • Nitro ProNitro Pro
  • cpe:2.3:a:gonitro:nitro_pro
NoYesOct 18, 2021
CVE-2021-21798HIGH7.8
  • Nitro ProNitro Pro
  • cpe:2.3:a:gonitro:nitro_pro
NoYesSep 15, 2021
CVE-2025-67825MEDIUM5.5
  • Nitro ProNitro Pro
  • cpe:2.3:a:gonitro:nitro_pdf_pro
NoYesJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management