Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-35262 | Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. CertUtil is run in a conhost.exe window, and there is a mechanism allowing CTRL+o to launch cmd.exe as NT AUTHORITY\SYSTEM. |
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 09 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gonitro
Gonitro nitro Pdf Pro |
|
| CPEs | cpe:2.3:a:gonitro:nitro_pdf_pro:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gonitro
Gonitro nitro Pdf Pro |
|
| Metrics |
cvssV3_1
|
Wed, 09 Oct 2024 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. CertUtil is run in a conhost.exe window, and there is a mechanism allowing CTRL+o to launch cmd.exe as NT AUTHORITY\SYSTEM. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-25T16:43:00.153Z
Reserved: 2024-05-15T00:00:00.000Z
Link: CVE-2024-35288
Updated: 2024-10-09T04:03:25.922Z
Status : Deferred
Published: 2024-10-09T04:15:08.233
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-35288
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD