HIGH🇵🇱 Wersja polska

CVE-2025-14406

CVSS 7.8v3.0pub. 2025-12-23upd. 2026-01-21

Soda PDF Desktop Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Soda PDF Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of OpenSSL. The product loads an OpenSSL configuration file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-25793.

CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Sodapdf Soda Pdf

    APP
    Sodapdf
    14.0.509.23030
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCELPE
CWE
References

Related vulnerabilities

CVE-2025-14409HIGH7.8same product

Soda PDF Desktop PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability ...

CVE-2025-14412HIGH7.8same product

Soda PDF Desktop XLS File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allo...

CVE-2025-14415HIGH7.8same product

Soda PDF Desktop Launch Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows...

CVE-2025-14410MEDIUM5.5same product

Luka typu Out-Of-Bounds Read w parsowaniu plików PDF w Soda PDF Desktop umożliwiająca ujawnienie poufnych info...

CVE-2025-14407MEDIUM5.5same product

Podatność w Soda PDF Desktop związana z parsowaniem plików PDF i ujawnieniem informacji. Podatność pozwala zda...