CVE-2026-2516
Unidocs ezPDF Reader vulnerability analysis and mitigation

Overview

CVE-2026-2516 is an uncontrolled search path (DLL hijacking) vulnerability affecting Unidocs ezPDF DRM Reader and ezPDF Reader versions 2.0 and 3.0.0.4. The flaw resides in an unknown code path within the SHFOLDER.dll library, where improper handling of the DLL search path allows a local attacker to substitute a malicious DLL. It was published on February 15, 2026, and carries a CVSS v3.1 base score of 7.0 (High) and a CVSS v4.0 base score of 7.3 (High) (Feedly, VulDB).

Technical details

The vulnerability is classified under CWE-426 (Untrusted Search Path) and CWE-427 (Uncontrolled Search Path Element). When ezPDF DRM Reader or ezPDF Reader loads SHFOLDER.dll, it does not enforce a fully qualified or trusted path, allowing an attacker with local access to place a malicious DLL in a directory that is searched before the legitimate system location. Exploitation requires low privileges and no user interaction, but is rated high complexity, consistent with MITRE ATT&CK techniques T1574.001 (DLL Search Order Hijacking) and T1574.007 (Path Interception by PATH Environment Variable). A proof-of-concept exploit is publicly available (Feedly, VulDB).

Impact

Successful exploitation grants an attacker high impact across confidentiality, integrity, and availability on the affected system, as the malicious DLL executes in the context of the vulnerable application. An attacker could achieve arbitrary code execution, access sensitive data processed by the PDF reader (including DRM-protected content), or cause application crashes. The scope is limited to the local system, with no direct lateral movement capability, though code execution could serve as a stepping stone for privilege escalation or further compromise (Feedly).

Exploitability

A proof-of-concept exploit is publicly available, raising the risk of weaponization despite the local-only attack vector and high complexity rating. The EPSS score is approximately 0.011% (0.000110), indicating a currently low probability of widespread exploitation. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly, VulDB).

Exploitation steps

  1. Reconnaissance: Identify systems running Unidocs ezPDF DRM Reader or ezPDF Reader versions 2.0 or 3.0.0.4 with local or remote desktop access.
  2. Identify DLL search path: Determine the directories searched by the application when loading SHFOLDER.dll (e.g., application directory, current working directory, directories in the PATH environment variable) using tools such as Process Monitor (Procmon) from Sysinternals.
  3. Craft malicious DLL: Compile a malicious SHFOLDER.dll that executes attacker-controlled code (e.g., a reverse shell or credential dumper) while optionally forwarding legitimate exports to avoid crashes.
  4. Place malicious DLL: Copy the crafted SHFOLDER.dll into a directory that is searched before the legitimate Windows system directory (e.g., the application's installation folder or a writable directory in the PATH), requiring only low-privilege local write access.
  5. Trigger execution: Launch or cause the target user to launch ezPDF DRM Reader or ezPDF Reader; the application loads the malicious DLL instead of the legitimate one, executing the attacker's payload in the application's security context (VulDB, Feedly).

Indicators of compromise

  • File System: Presence of an unexpected SHFOLDER.dll in the ezPDF application installation directory or any directory listed in the system/user PATH environment variable; file hash mismatch compared to the legitimate Microsoft SHFOLDER.dll.
  • Process: Unusual child processes spawned by the ezPDF Reader process (e.g., cmd.exe, powershell.exe, network tools); unexpected network connections originating from the ezPDF Reader process.
  • Logs: Windows Event Logs (Security/System) showing DLL load events from non-standard paths for SHFOLDER.dll; Sysmon Event ID 7 (Image Loaded) entries showing SHFOLDER.dll loaded from a path other than %SystemRoot%\System32\.
  • Network: Outbound connections from the ezPDF Reader process to unknown external IP addresses or domains, particularly shortly after application launch (VulDB).

Mitigation and workarounds

Unidocs recommends upgrading to the latest version of ezPDF DRM Reader or ezPDF Reader, stating that similar DLL search path vulnerability patterns have been addressed in prior security updates. As a workaround, administrators should ensure the application's installation directory and all directories in the PATH environment variable are not writable by unprivileged users. Additionally, enabling Windows Safe DLL Search Mode and using application whitelisting (e.g., AppLocker) can reduce the risk of DLL hijacking attacks (Feedly, VulDB).

Community reactions

The vulnerability received coverage from automated security aggregators and community feeds, including VulDB, Vulners, and CIRCL. The VulDB Mastodon account (@vuldb) posted a notification, and the offseq threat radar platform flagged it for tracking. No notable independent researcher commentary or major media coverage has been identified beyond standard aggregation (VulDB Mastodon, offseq).

Additional resources


SourceThis report was generated using AI

Related Unidocs ezPDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-7870HIGH7.2
  • Unidocs ezPDF Editor logoUnidocs ezPDF Editor
  • cpe:2.3:a:unidocs:ezpdf_editor
NoYesJun 29, 2021
CVE-2026-2516MEDIUM6.4
  • Unidocs ezPDF Reader logoUnidocs ezPDF Reader
  • cpe:2.3:a:unidocs:ezpdf_reader
NoNoFeb 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management