CVE-2025-30057

Severity CVSS v4.0:
CRITICAL
Type:
CWE-94 Code Injection
Publication date:
27/08/2025
Last modified:
29/08/2025

Description

In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() call in the ConvertToPDF function.

References to Advisories, Solutions, and Tools