CVE-2025-14406: (0Day) Soda PDF Desktop Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Soda PDF Desktop Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Soda PDF Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of OpenSSL. The product loads an OpenSSL configuration file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-25793.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14406?
CVE-2025-14406 is classified as a local privilege escalation vulnerability.
How do I fix CVE-2025-14406?
To fix CVE-2025-14406, ensure that you update Soda PDF Desktop to the latest version provided by the vendor.
Who is affected by CVE-2025-14406?
CVE-2025-14406 affects installations of Soda PDF Desktop on systems where attackers can execute low-privileged code.
What causes CVE-2025-14406?
CVE-2025-14406 is caused by an uncontrolled search path element which allows privilege escalation.
Can CVE-2025-14406 be exploited remotely?
No, CVE-2025-14406 requires local access to the affected system for exploitation.