
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14418 is a remote code execution vulnerability in pdfforge PDF Architect caused by insufficient UI warnings when processing XLS files. It was discovered by researcher kimiya and reported to the vendor on July 10, 2025. After the vendor failed to provide a patch, ZDI published it as a 0-day advisory on December 11, 2025. The vulnerability affects PDF Architect version 9.1.74.23030 and carries a CVSS v3.0 base score of 7.0 (High) (ZDI Advisory).
The vulnerability is classified as CWE-356 (Product UI Does Not Warn User of Unsafe Actions). When PDF Architect processes a malicious XLS file, it executes embedded dangerous scripts without presenting any warning to the user, bypassing expected security prompts. Exploitation requires the target to open a malicious XLS file or visit a malicious page that triggers the file processing. The flaw was tracked internally as ZDI-CAN-27502 (ZDI Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the context of the currently logged-in user, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could read sensitive files, modify data, install malware, or disrupt application availability — all without requiring elevated privileges. The scope is limited to the local user context, but could serve as a foothold for further lateral movement in enterprise environments (ZDI Advisory).
This vulnerability was published as a 0-day advisory on December 11, 2025, meaning no vendor patch was available at the time of disclosure. Exploitation requires user interaction (opening a malicious XLS file or visiting a malicious page), and the attack complexity is rated High due to local attack vector constraints. The EPSS score is approximately 0.066%, indicating a low but non-zero probability of exploitation in the wild. No evidence of active in-the-wild exploitation or CISA KEV catalog listing has been reported as of the available data (ZDI Advisory).
cmd.exe, powershell.exe, wscript.exe, or network utilities like curl or wget).As of the 0-day disclosure on December 11, 2025, no vendor patch was available. ZDI's recommended mitigation is to restrict interaction with pdfforge PDF Architect until a fix is released. Users should avoid opening untrusted XLS files with PDF Architect, apply network-level controls to limit exposure, and monitor for suspicious process activity. Organizations should check pdfforge's official channels for any subsequent patch releases and prioritize upgrading once a fixed version becomes available (ZDI Advisory).
The vulnerability was disclosed as a 0-day by the Zero Day Initiative after the vendor, pdfforge, failed to provide a patch within the standard coordinated disclosure window despite multiple follow-up attempts over five months. ZDI notified the vendor of its intent to publish on December 5, 2025, and released the advisory on December 11, 2025. No significant public commentary from pdfforge or notable community discussion has been identified beyond standard vulnerability aggregator coverage (ZDI Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."