CVE-2025-14420
PDF Architect vulnerability analysis and mitigation

Overview

CVE-2025-14420 is a directory traversal vulnerability in pdfforge PDF Architect that enables remote attackers to execute arbitrary code on affected installations. The flaw resides in the parsing of CBZ (Comic Book ZIP) files, where user-supplied path values are not properly validated before being used in file operations. It was reported to the vendor on August 12, 2025, and publicly disclosed as a zero-day advisory on December 11, 2025, after the vendor did not respond to multiple follow-ups. The affected version is PDF Architect 9.1.74.23030, and the vulnerability carries a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory).

Technical details

The root cause is improper limitation of a pathname to a restricted directory (CWE-22 / Path Traversal). When PDF Architect parses a CBZ file — which is essentially a ZIP archive — it fails to sanitize embedded file paths before performing file system operations, allowing an attacker to write files to arbitrary locations outside the intended directory. Exploitation requires the target user to open a specially crafted malicious CBZ file or visit a page that triggers its processing. The vulnerability was tracked internally by ZDI as ZDI-CAN-27514 and credited to researcher kimiya (ZDI Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the currently logged-in user, resulting in high confidentiality, integrity, and availability impact. An attacker could write malicious files to sensitive locations (e.g., startup folders, application directories) to achieve persistence or escalate privileges, and could access or exfiltrate data accessible to the user. The scope is limited to the local system of the victim, but lateral movement is possible if the compromised user account has network access or elevated privileges (ZDI Advisory).

Exploitability

This vulnerability was published as a zero-day advisory on December 11, 2025, meaning no vendor patch was available at the time of disclosure. No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.119%, indicating a low probability of near-term exploitation, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction — the victim must open a malicious CBZ file — which somewhat limits the attack surface (ZDI Advisory, Feedly).

Exploitation steps

  1. Craft malicious CBZ file: Create a ZIP archive (renamed with a .cbz extension) containing a file with a path-traversal sequence in its filename, such as ../../AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup/malicious.exe, embedding a malicious executable payload.
  2. Deliver the file: Distribute the malicious CBZ file to the target via phishing email, a malicious web page offering a download, or another social engineering vector that prompts the user to open the file.
  3. Trigger parsing: When the victim opens the CBZ file in pdfforge PDF Architect, the application parses the archive and processes the embedded file paths without proper sanitization.
  4. Achieve path traversal: The unsanitized path causes PDF Architect to write the malicious payload to an attacker-controlled location outside the intended extraction directory (e.g., a startup folder or application directory).
  5. Execute arbitrary code: The dropped payload executes in the context of the current user — either immediately or upon the next system/application restart — granting the attacker code execution on the victim's machine (ZDI Advisory).

Indicators of compromise

  • File System: Unexpected files written to directories outside the normal CBZ extraction path, particularly in %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\, %TEMP%, or application directories; newly created executables or scripts with unusual names in user-writable locations.
  • Process: Unexpected child processes spawned by the PDF Architect process (e.g., cmd.exe, powershell.exe, or unknown executables); PDF Architect process accessing file paths containing ..\ or ../ sequences.
  • Logs: Windows Event Logs showing new file creation events in sensitive directories initiated by the PDF Architect process; application crash logs or errors related to file path handling in PDF Architect.
  • Network: Outbound network connections from the PDF Architect process or newly dropped executables to unknown external IP addresses or domains shortly after opening a CBZ file.

Mitigation and workarounds

As of the zero-day disclosure date (December 11, 2025), no vendor patch was available; ZDI noted that the vendor did not provide a fix despite coordinated disclosure attempts beginning August 12, 2025. ZDI's recommended mitigation is to restrict interaction with PDF Architect, particularly avoiding opening CBZ files from untrusted sources. Users should apply the principle of least privilege to limit the impact of potential exploitation, and organizations should monitor for and block delivery of unsolicited CBZ files via email gateways. Users are advised to check pdfforge's official channels for any subsequent patch releases (ZDI Advisory).

Community reactions

The vulnerability was disclosed by the Zero Day Initiative (Trend Micro) as a zero-day after the vendor failed to respond adequately to multiple follow-up attempts over four months. The ZDI disclosure timeline highlights a breakdown in coordinated disclosure, with ZDI notifying pdfforge of its intent to publish before receiving a patch. No significant public commentary from the broader security community or media coverage beyond standard vulnerability database aggregation has been identified (ZDI Advisory).

Additional resources


SourceThis report was generated using AI

Related PDF Architect vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14420HIGH7.8
  • PDF Architect logoPDF Architect
  • cpe:2.3:a:pdfforge:pdf_architect
NoNoDec 23, 2025
CVE-2025-14419HIGH7.8
  • PDF Architect logoPDF Architect
  • cpe:2.3:a:pdfforge:pdf_architect
NoNoDec 23, 2025
CVE-2025-14417HIGH7.8
  • PDF Architect logoPDF Architect
  • cpe:2.3:a:pdfforge:pdf_architect
NoNoDec 23, 2025
CVE-2025-14418HIGH7
  • PDF Architect logoPDF Architect
  • cpe:2.3:a:pdfforge:pdf_architect
NoNoDec 23, 2025
CVE-2025-14421MEDIUM5.5
  • PDF Architect logoPDF Architect
  • cpe:2.3:a:pdfforge:pdf_architect
NoNoDec 23, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management