HIGH🇵🇱 Wersja polska

CVE-2025-14412

CVSS 7.8v3.0pub. 2025-12-23upd. 2026-01-21

Soda PDF Desktop XLS File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Soda PDF Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of XLS files. The issue results from allowing the execution of dangerous script without user warning. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27495.

CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Sodapdf Soda Pdf

    APP
    Sodapdf
    14.0.509.23030
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2025-14415HIGH7.8same product

Soda PDF Desktop Launch Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows...

CVE-2025-14406HIGH7.8same product

Soda PDF Desktop Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability...

CVE-2025-14409HIGH7.8same product

Soda PDF Desktop PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability ...

CVE-2025-14410MEDIUM5.5same product

Luka typu Out-Of-Bounds Read w parsowaniu plików PDF w Soda PDF Desktop umożliwiająca ujawnienie poufnych info...

CVE-2025-14411MEDIUM5.5same product

Podatność ujawniania informacji z powodu wychodzenia poza granice pamięci w Soda PDF Desktop podczas parsowani...