Description
In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() call in the ConvertToPDF function.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
Any version before 2024.MS4
Credits
Maciej Kazulak
References
cert.pl/en/posts/2025/08/CVE-2025-2313/