CVE-2021-26605

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
05/08/2021
Last modified:
13/08/2021

Description

An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. This issue occurred when the ezPDF launcher received and executed crafted input values through JSON-RPC communication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:unidocs:ezpdfreader:*:*:*:*:*:*:*:* 2.0 (including) 3.0 (including)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*