CVE-2024-35288
Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. CertUtil is run in a conhost.exe window, and there is a mechanism allowing CTRL+o to launch cmd.exe as NT AUTHORITY\SYSTEM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35288?
CVE-2024-35288 has a high severity rating due to the potential for local privilege escalation.
How do I fix CVE-2024-35288?
To fix CVE-2024-35288, upgrade Nitro PDF Pro to version 13.70.8.82 or 14.26.1.0 or later.
What types of systems are affected by CVE-2024-35288?
CVE-2024-35288 affects versions of Nitro PDF Pro prior to 13.70.8.82 and 14.x before 14.26.1.0.
What is the impact of exploiting CVE-2024-35288?
Exploiting CVE-2024-35288 allows attackers to execute commands with system-level privileges.
How does CVE-2024-35288 enable privilege escalation?
CVE-2024-35288 enables privilege escalation through unsafe custom actions during repair mode that execute commands as NT AUTHORITY\SYSTEM.