Junglewise Threat Intelligence

CVE-2026-13522: Investintech SlimPDFReader out-of-bounds read in PDF File Handler

CVE-2026-13522 · Severity: medium · CVSS 4.3 · Published 2026-06-29

Executive brief

Investintech SlimPDFReader is a lightweight application used for viewing PDF documents. A security flaw in the software's file handling component could allow a remote attacker to crash the application by tricking a user into opening a specially crafted PDF file. This could lead to a denial-of-service for the user, though the product is no longer supported by the manufacturer.

Technical details

An out-of-bounds read vulnerability exists in Investintech SlimPDFReader up to version 2.0.14. The flaw is located within the PDF File Handler component, specifically in the function Investintech::PCV::TeighaDo in SlimPDFReader.exe. A remote attacker can exploit this by providing a manipulated PDF file that, when opened by a user, causes the application to read memory outside of the intended buffer. This typically results in an application crash (denial of service). The vulnerability is categorized under CWE-125 and CWE-119. No patch is expected as the product is end-of-life.

Affected products

  • Investintech SlimPDFReader up to 2.0.14

Timeline

  • 2026-06-29: disclosed
  • 2026-06-29: advisory

References

Related threats