CVE detail
CVE-2023-49147 — CVE-2023-49147
Published 2023-12-19 · Modified 2026-06-17 · Vendor pdf24 · Product pdf24_creator · Source nvd
HIGH
severity
CVSS-derived band
0.0048
EPSS probability
exploitation probability, 30d
39.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An issue was discovered in PDF24 Creator 11.14.0. The configuration of the msi installer file was found to produce a visible cmd.exe window when using the repair function of msiexec.exe. This allows an unprivileged local attacker to use a chain of actions (e.g., an oplock on faxPrnInst.log) to open a SYSTEM cmd.exe.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References