CVE-2026-23512
Last modified
CVE-2026-23512 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability when Advanced Options setting is trigger. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability when Advanced Options setting is trigger. The application executes notepad.exe without specifying an absolute path when using the Advanced Options setting. On Windows, this allows execution of a malicious notepad.exe placed in the application's installation directory, leading to arbitrary code execution.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sumatrapdfreader | Sumatrapdf | <= 3.5.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-23512?
How severe is CVE-2026-23512?
How do I fix CVE-2026-23512?
Are you affected by CVE-2026-23512?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
